Linkwhisper is a WordPress SEO plugin with a narrowly scoped product line centered on its core link-analysis tool, with reported vulnerabilities centered on input-handling and authentication deficiencies such as SQL injection and missing authentication controls on critical functions. Treat this as a compact vendor profile rather than a broad trend line; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Linkwhisper over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-1900MEDIUM The Link Whisper Free WordPress plugin before 0.9.1 has a publicly accessible REST endpoint that allows unauthenticated settings updates. | Apr 7, 2026 | 6.5 | 23 | NO | NO |
CVE-2023-47852HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Link Whisper Link Whisper Free.This issue affects Link Whisper Free: from n/a | Dec 20, 2023 | 7.2 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Linkwhisper.
Media articles that mention a CVE ID that affects a product developed by Linkwhisper — matched by CVE ID, not by vendor name.