SQL Injection Vulnerability in ClickWhale Link Manager Plugin for WordPress
CVE-2025-10002

4.9MEDIUM

What is CVE-2025-10002?

The ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages plugin for WordPress is exposed to an SQL Injection vulnerability via the export_csv() function. This issue arises from inadequate escaping of user-supplied parameters and insufficient preparation of existing SQL queries. Authenticated attackers with Administrator-level access can manipulate SQL queries, thereby allowing them to extract sensitive information from the database. Furthermore, there's a potential risk for lower-level users if they are granted access to the plugin, raising concerns about overall plugin security.

Affected Version(s)

ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages * <= 2.5.0

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Naoya Takahashi
.
CVE-2025-10002 : SQL Injection Vulnerability in ClickWhale Link Manager Plugin for WordPress