Vulnerabilities > Flowdee > Clickwhale > 1.4.1

DATE CVE VULNERABILITY TITLE RISK
2025-01-11 CVE-2024-11327 Cross-site Scripting vulnerability in Flowdee Clickwhale
The ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.4.1.
network
low complexity
flowdee CWE-79
6.1