Medium 6.1
2026-05-01< 1.10.5.1
CVE-2024-13362
Minimum safe version
1.12.4
Update to 1.12.4 or later to address 15 fixable vulnerabilities
CVE-2024-13362
URL Shortify <= 1.12.1 - Unauthenticated Open Redirect via 'redirect_to' Parameter
CVE-2026-25385
CVE-2025-13355
CVE-2025-12684
CVE-2025-32134
Freemius SDK <= 2.4.2 - Missing Authorization Checks
URL Shortify <= 1.7.9 - Authenticated (Admin+) Stored Cross-Site Scripting
CVE-2023-4294
WordPress URL Shortify Plugin < 1.7.4 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-3129
Freemius SDK <= 2.4.2 - Missing Authorization Checks
WordPress URL Shortify plugin < 1.5.11 - Sensitive Information Disclosure vulnerability
WordPress URL Shortify plugin < 1.5.11 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability
CVE-2021-24749