plugin

Change Wp Page Permalinks Vulnerabilities

1 known security issue reported for the Change Wp Page Permalinks WordPress plugin. Most recent disclosed Jan 8, 2026.

1 medium

Running Change Wp Page Permalinks on your site? Check whether your installed version is affected.

Scan your site free

WP Page Permalink Extension <= 1.5.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Rewrite Rules Flush

medium

The WP Page Permalink Extension plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.5.4. This is due to missing authorization checks on the `cwpp_trigger_flush_rewrite_rules` function hooked to `wp_ajax_cwpp_trigger_flush_rewrite_rules`. This makes it possible for authent...

CVSS:
6.5
Affected:
up to 1.5.4
Fix:
No patched version reported
Disclosed:
Jan 8, 2026

CVE-2025-14172 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database