Bitly's WordPress Plugin

Bitly's WordPress Plugin has 4 disclosed vulnerabilities in the WordSec catalog, reported between 2023 and 2025; 3 are fixed and 1 remains unpatched as of September 2026. Their average CVSS score is 5.6, and the most serious one scores 6.4 out of 10. 2025 was the busiest year with 2 disclosures.

The most common weakness is Cross-Site Scripting, behind 2 of the records (50%). Other recurring categories include Missing Authorization.

3 of the records (75%) have a vendor fix, while 1 remain unpatched. The oldest unresolved one dates back to 2025.

4 independent researchers contributed these findings, one record each. Bitly's WordPress Plugin is installed on roughly 2,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.7.7.

Strategic Overview

Avg CVSSMedium
5.6/ 10
Patch Coverage75%
Open

1

Fixed

3

Get automatic notifications for all Bitly's WordPress Plugin vulnerabilities before they are exploited.

Most severe open issueCVSS 6.4CVE-2025-58231

Bitly <= 2.7.4 - Authenticated (Contributor+) Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

4 records
Bitly's WordPress Plugin banner
Latestv2.8.1

Bitly's WordPress Plugin

bitlydeveloper

Author

bitlydeveloper

4.2(23)
84/100
Last Updated
2026-03-10 (6mo ago)
Active Installs
2,000+
Downloads
145,511
Requires WP
5.0+
Requires PHP
0+
Tested up to
WP 6.7.7
Created
2010-04-02 (17y ago)

Love WordPress? Love Bitly? After installing this plugin, you’ll be able to shorten a link and view clicks right from WordPress. Your new links will be saved to Bitly for reference and deeper analysis. To do that, you must have a Bitly account to use the plugin. Your account is where you store, edit, and view metrics for your links. Register at bitly.com. No matter the type of site you own (from a personal blog to an ecommerce store and everything in between) Bitly makes it easy to create shorter links and keep an eye on your clicks. Whether you share your links on social, SMS, or email, a short link is easier to manage and remember.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C