Link Hopper

Link Hopper has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it remains unpatched as of September 2026. Their average CVSS score is 4.4, and the most serious one scores 4.4 out of 10.

The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).

The one issue recorded for Link Hopper has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2026.

All of these findings were reported by ZAST.AI. Link Hopper is installed on roughly 100 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.

Strategic Overview

Avg CVSSMedium
4.4/ 10
Patch Coverage0%
Open

1

Fixed

0

Get automatic notifications for all Link Hopper vulnerabilities before they are exploited.

Most severe open issueCVSS 4.4CVE-2025-15483

Link Hopper <= 2.5 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'hop_name' Parameter

Read the full analysis

Vulnerability Records

1 records
Plugin Profile
Latestv3.0

Link Hopper

Anthony

Author

Anthony

0.0(0)
0/100
Last Updated
2026-03-08 (6mo ago)
Active Installs
100+
Downloads
16,499
Requires WP
6.0+
Requires PHP
8.3+
Tested up to
WP 6.9.7
Created
2009-03-28 (18y ago)

Easily set up links like /hop/google/ to redirect users to www.google.com. This can be useful in masking your affiliate links. If your affiliate link needs to change, you can just change the HOP values in a single place, without having to search your site for outdated links.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C