The Wp No External Links Project maintains a WordPress plugin focused on managing external link behavior, a narrowly scoped product that serves site administrators seeking to control outbound link handling. Vulnerabilities in this plugin have centered on cross-site scripting issues arising from improper input neutralization during web page generation, a typical concern for WordPress components that process user-controlled content. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wp No External Links Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-15863MEDIUM Cross Site Scripting (XSS) exists in the wp-noexternallinks plugin before 3.5.19 for WordPress via the date1 or date2 parameter to wp-admin/options-general.php. | Oct 24, 2017 | 6.1 | 21 | NO | NO |
CVE-2023-26537MEDIUM Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in nicolly WP No External Links plugin <= 1.0.2 versions. | Jun 16, 2023 | 4.8 | 16 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wp No External Links Project.
Media articles that mention a CVE ID that affects a product developed by Wp No External Links Project — matched by CVE ID, not by vendor name.