Bitly's WordPress Plugin
Bitly's WordPress Plugin has 4 disclosed vulnerabilities in the WordSec catalog, reported between 2023 and 2025; 3 are fixed and 1 remains unpatched as of September 2026. Their average CVSS score is 5.6, and the most serious one scores 6.4 out of 10. 2025 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Scripting, behind 2 of the records (50%). Other recurring categories include Missing Authorization.
3 of the records (75%) have a vendor fix, while 1 remain unpatched. The oldest unresolved one dates back to 2025.
4 independent researchers contributed these findings, one record each. Bitly's WordPress Plugin is installed on roughly 2,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.7.7.
CVE-2025-58231Bitly <= 2.7.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

Bitly's WordPress Plugin
Author
bitlydeveloper
Love WordPress? Love Bitly? After installing this plugin, you’ll be able to shorten a link and view clicks right from WordPress. Your new links will be saved to Bitly for reference and deeper analysis. To do that, you must have a Bitly account to use the plugin. Your account is where you store, edit, and view metrics for your links. Register at bitly.com. No matter the type of site you own (from a personal blog to an ecommerce store and everything in between) Bitly makes it easy to create shorter links and keep an eye on your clicks. Whether you share your links on social, SMS, or email, a short link is easier to manage and remember.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C