Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Link Whisper Free — Vulnerabilities & Security Advisories 13

All 13 CVE vulnerabilities found in Link Whisper Free, with AI-generated Chinese analysis, references, and POCs.

This page tracks common vulnerability classifications associated with the Link Whisper Free WordPress plugin developed by Link Whisper. It aggregates security weaknesses including cross-site scripting, broken access control, and insecure default configurations that may affect the integrity and confidentiality of websites utilizing this specific tool. The content encompasses reported security issues from early 2021 through mid-2024, providing a historical overview of known flaws and their resolution timelines. Readers can utilize this resource to track vendor advisories and monitor how the developer addresses emerging security concerns over time. The aggregation allows for a deeper understanding of a specific weakness class by examining its manifestation within this particular ecosystem rather than in isolation. Users may look up the product's vulnerability history to identify patterns, such as recurring input validation errors or permission handling deficiencies, that have persisted across different versions. This structured approach facilitates the assessment of risk exposure for systems currently running Link Whisper Free. It serves as a reference point for security analysts evaluating the plugin's safety record and for administrators seeking context before updating or replacing the software. The data is organized to highlight the severity and scope of each reported issue without recommending specific remediation steps, leaving those decisions to the discretion of the site owners and security teams responsible for maintaining the environment.

Vendor: Link Whisper

CVE IDTitleCVSSSeverityPublished
CVE-2026-57333 WordPress Link Whisper Free plugin <= 0.9.4 - Reflected Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High2026-06-29
CVE-2025-11262 Link Whisper Free <= 0.9.0 - Unauthenticated Stored Cross-Site Scripting CWE-79 7.2 High2026-05-29
CVE-2026-1900 Link Whisper Free < 0.9.1 - Unauthenticated Settings and User Meta Update 5.3AIMediumAI2026-04-07
CVE-2026-22357 WordPress Link Whisper Free plugin <= 0.9.2 - Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High2026-02-20
CVE-2025-67927 WordPress Link Whisper Free plugin <= 0.8.8 - Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High2026-01-08
CVE-2025-11263 Link Whisper Free <= 0.8.8 - Reflected Cross-Site Scripting CWE-79 6.1 Medium2025-12-06
CVE-2025-62970 WordPress Link Whisper Free plugin <= 0.9.2 - Broken Access Control vulnerability CWE-862 5.3 Medium2025-10-27
CVE-2025-22306 WordPress Link Whisper Free plugin <= 0.7.7 - Sensitive Data Exposure vulnerability CWE-538 5.3 Medium2025-01-07
CVE-2023-32506 WordPress Link Whisper Free plugin <= 0.6.3 - Unauthenticated Broken Access Control vulnerability CWE-862 6.5 Medium2024-12-13
CVE-2024-31934 WordPress Link Whisper Free plugin <= 0.6.9 - Cross Site Request Forgery (CSRF) vulnerability CWE-352 4.3 Medium2024-04-11
CVE-2024-2693 Link Whisper Free <= 0.7.1 - Authenticated (Contributor+) PHP Object Injection CWE-502 8.8 High2024-04-09
CVE-2024-27992 WordPress Link Whisper Free plugin <= 0.6.8 - Reflected Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High2024-03-21
CVE-2023-47852 WordPress Link Whisper Free Plugin <= 0.6.5 is vulnerable to SQL Injection CWE-89 8.5 High2023-12-20

All 13 known CVE vulnerabilities affecting Link Whisper Free with full Chinese analysis, references, and POCs where available.