SQL Injection Vulnerability in ClickWhale Link Manager Plugin for WordPress
CVE-2025-10002
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 20 September 2025
What is CVE-2025-10002?
The ClickWhale β Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages plugin for WordPress is exposed to an SQL Injection vulnerability via the export_csv() function. This issue arises from inadequate escaping of user-supplied parameters and insufficient preparation of existing SQL queries. Authenticated attackers with Administrator-level access can manipulate SQL queries, thereby allowing them to extract sensitive information from the database. Furthermore, there's a potential risk for lower-level users if they are granted access to the plugin, raising concerns about overall plugin security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
ClickWhale β Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages * <= 2.5.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved