Link Hopper
Link Hopper has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it remains unpatched as of September 2026. Their average CVSS score is 4.4, and the most serious one scores 4.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Link Hopper has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2026.
All of these findings were reported by ZAST.AI. Link Hopper is installed on roughly 100 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.
CVE-2025-15483Link Hopper <= 2.5 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'hop_name' Parameter
Read the full analysisVulnerability Records
Link Hopper
Author
Anthony
Easily set up links like /hop/google/ to redirect users to www.google.com. This can be useful in masking your affiliate links. If your affiliate link needs to change, you can just change the HOP values in a single place, without having to search your site for outdated links.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C