WPIntell

Source evidence

Cross Site Scripting (XSS) Vulnerability

Link Whisper Free · support · 2026-03-03T14:08:00+00:00

complaintsentiment
highseverity
1.0relevance
3replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

5 / 34 rows with source links

14.7% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

29 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
ChrisL unresolved
Patchstack reports that the latest version (0.9.1) is still vulnerable: https://patchstack.com/database/wordpress/plugin/link-whisper/vulnerability/wordpress-link-whisper-free-plugin-0-9-0-reflected-cross-site-scripting-xss-vulnerability Hey Chris, Thanks for pointing that out and for sharing the Patchstack link. I’ve released a fix for the vulnerability in the 0.9.2 update of Link Whisper Free . If you update to that version, the issue should be resolved. It may take a day or two for Patchstack to review and verify the fix on their end, so their database may still show the previous status for a short time. But the patch is already included in the latest update. Appreciate you bringing it up. Warm regards, Matt Thanks for the update! Chris Hi Matt, Are you aware that Patchstack is still listing the plugin as vulnerable, up to and including the latest version? WordPress Link Whisper Free Plugin <= 0.9.2 is vulnerable to a medium priority Cross Site Scripting (XSS) https://patchstack.com/database/wordpress/plugin/link-whisper/vulnerability/wordpress-link-whisper-free-plugin-0-9-0-reflected-cross-site-scripting-xss-vulnerability

Comments

3 shown
Matt_Bissett 2026-03-06T06:17:00+00:00

Hey Chris, Thanks for pointing that out and for sharing the Patchstack link. I’ve released a fix for the vulnerability in the 0.9.2 update of Link Whisper Free . If you update to that version, the issue should be resolved. It may take a day or two for Patchstack to review and verify the fix on their end, so their database may still show the previous status for a short time. But the patch is already included in the latest update. Appreciate you bringing it up. Warm regards, Matt

ChrisL 2026-03-06T12:42:00+00:00

Thanks for the update! Chris

ChrisL 2026-03-28T08:52:00+00:00

Hi Matt, Are you aware that Patchstack is still listing the plugin as vulnerable, up to and including the latest version? WordPress Link Whisper Free Plugin <= 0.9.2 is vulnerable to a medium priority Cross Site Scripting (XSS) https://patchstack.com/database/wordpress/plugin/link-whisper/vulnerability/wordpress-link-whisper-free-plugin-0-9-0-reflected-cross-site-scripting-xss-vulnerability