Campaign URL Builder
Campaign URL Builder has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2023; all 2 are fixed as of September 2026. Their average CVSS score is 5.4, and the most serious one scores 6.4 out of 10. 2023 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Scripting, behind 2 of the records (100%).
Every one of the 2 issues recorded for Campaign URL Builder has a vendor fix available, so running the current release closes all known holes.
All of these findings were reported by István Márton. Campaign URL Builder is installed on roughly 100 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.1.12.
CVE-2023-0538Campaign URL Builder <= 1.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Read the full analysisVulnerability Records

Campaign URL Builder
Author
Alex Zappa
Generates links for Analytics tools and short link. Enter your Campaign Name, Source, Medium (UTM link) etc. to generate a full link and a short link (through the Google URL Shortener API) all in once. https://ga-dev-tools.appspot.com/campaign-url-builder/ Available languages : * English * Russian
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C