Link View
Link View has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2025; none of them are fixed as of September 2026. Their average CVSS score is 5.4, and the most serious one scores 6.4 out of 10. 2025 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Scripting, behind 2 of the records (100%).
None of the 2 issues recorded for Link View have a published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
2 independent researchers contributed these findings, one record each. Link View is installed on roughly 700 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 5.6.19.
CVE-2025-48110Link View <= 0.8.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

Link View
Author
mibuthu
The purpose of this plugin is to to show the wordpress integrated links in a list or a slider by using a shortcode or a widget. Current Features: the shortcode [linkview] can be used to add the links in a post or page the widget “LinkView” can be used to add links in a sidebar the links can be displayed in a list or in a slider there are many options available to adjust the output of the links (see shortcode options in the “About LinkView” page) the image of the link can also be displayed categories and/or links can be displayed in multicolumn layout option to set additional css styles for the link-lists and link-sliders the required user roles to edit links can be adjusted in the settings page Development: If you want to follow the development status have a look at the git-repository on github. Feel free to add your merge requests there, if you want to help to improve the plugin. Translations: Please help translating this plugin into multiple languages. You can submit your translations at transifex.com. There the source strings will be kept in sync with the actual development version. And in each plugin release the available translation files will be updated.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C