plugin

Permalinks Customizer Vulnerabilities

2 known security issues reported for the Permalinks Customizer WordPress plugin. Most recent disclosed Nov 14, 2023.

2 medium

Running Permalinks Customizer on your site? Check whether your installed version is affected.

Scan your site free

Permalinks Customizer <= 2.8.2 - Reflected Cross-Site Scripting

medium

The Permalinks Customizer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown parameter in all versions up to, and including, 2.8.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages th...

CVSS:
6.1
Affected:
up to 2.8.2
Fix:
No patched version reported
Disclosed:
Nov 14, 2023

CVE-2023-47773 on NVD →

Permalinks Customizer <= 2.8.2 - Cross-Site Request Forgery via post_settings

medium

The Permalinks Customizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.8.2. This is due to missing or incorrect nonce validation on the post_settings function. This makes it possible for unauthenticated attackers to flush rewrite rules via a forged request granted...

CVSS:
4.3
Affected:
up to 2.8.2
Fix:
No patched version reported
Disclosed:
Oct 6, 2023

CVE-2023-45103 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database