plugin

Pretty Link Vulnerabilities

9 known security issues reported for the Pretty Link WordPress plugin. Most recent disclosed Aug 4, 2026.

3 high 6 medium

Running Pretty Link on your site? Check whether your installed version is affected.

Scan your site free

PrettyLinks <= 3.6.20 - Authenticated (Administrator+) SQL Injection via 's' Parameter

medium

The PrettyLinks – Affiliate Links, Link Branding, Link Tracking, Marketing and Stripe Payments Plugin plugin for WordPress is vulnerable to SQL Injection via the 's' (search) parameter on the Pretty Links listing page in all versions up to, and including, 3.6.20. This is due to insufficient escaping on the user supplie...

CVSS:
4.9
Affected:
up to 3.6.20
Fixed in:
3.6.21
Disclosed:
Aug 4, 2026

CVE-2026-5062 on NVD →

Shortlinks by Pretty Links <= 3.6.15 - Missing Authorization

medium

The PrettyLinks – Affiliate Links, Link Branding, Link Tracking, Marketing and Stripe Payments Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the search_results() function in all versions up to, and including, 3.6.15. This makes it possible for authenticated attack...

CVSS:
4.3
Affected:
up to 3.6.15
Fixed in:
3.6.16
Disclosed:
May 19, 2025

CVE-2025-48247 on NVD →

Shortlinks by Pretty Links <= 3.6.2 - Reflected Cross-Site Scripting via post_status

medium

The Shortlinks by Pretty Links plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘post_status’ parameter in versions up to, and including, 3.6.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in...

CVSS:
6.1
Affected:
up to 3.6.2
Fixed in:
3.6.3
Disclosed:
Mar 25, 2024

CVE-2024-29770 on NVD →

Pretty Links – Affiliate Links, Link Branding, Link Tracking & Marketing Plugin <= 3.6.3 - Cross-Site Request Forgery to Plugin Settings Update

medium

The Pretty Links – Affiliate Links, Link Branding, Link Tracking & Marketing Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.3. This is due to missing or incorrect nonce validation when saving plugin settings. This makes it possible for unauthenticated a...

CVSS:
4.3
Affected:
up to 3.6.3
Fixed in:
3.6.4
Disclosed:
Mar 22, 2024

CVE-2024-2326 on NVD →

Shortlinks by Pretty Links <= 3.4.0 - Cross-Site Request Forgery via route

medium

The Shortlinks by Pretty Links plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4.0. This is due to missing or incorrect nonce validation on the route function. This makes it possible for unauthenticated attackers to clear link visit stats via a forged request granted...

CVSS:
4.3
Affected:
up to 3.4.0
Fixed in:
3.4.1
Disclosed:
Apr 13, 2023

CVE-2022-47149 on NVD →

Pretty Links <= 2.1.9 - Unauthenticated Stored Cross-Site Scripting via track_link

high

The Pretty Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting via various IP headers as well as the referer header in versions up to, and including, 2.1.9 due to insufficient input sanitization and output escaping in the track_link function. This makes it possible for unauthenticated attackers to i...

CVSS:
7.2
Affected:
up to 2.1.10
Fixed in:
2.1.10
Disclosed:
Jun 19, 2019

CVE-2019-25147 on NVD →

Pretty Links – Link Management, Branding, Tracking & Sharing Plugin <= 1.6.7 - SQL Injection

high

The pretty-link plugin before 1.6.8 for WordPress has PrliLinksController::list_links SQL injection via the group parameter.

CVSS:
7.2
Affected:
up to 1.6.8
Fixed in:
1.6.8
Disclosed:
Jul 8, 2015

CVE-2015-9457 on NVD →

Pretty Links Lite < 1.6.3 - Stored Cross-Site Scripting

high

Cross-site scripting (XSS) vulnerability in open-flash-chart.swf in Open Flash Chart (aka Open-Flash Chart), as used in the Pretty Link Lite plugin before 1.6.3 for WordPress, JNews (com_jnews) component 8.0.1 for Joomla!, and CiviCRM 3.1.0 through 4.2.9 and 4.3.0 through 4.3.3, allows remote attackers to inject arbitr...

CVSS:
7.2
Affected:
up to 1.6.3
Fixed in:
1.6.3
Disclosed:
Aug 1, 2014

CVE-2013-1636 on NVD →

Pretty Links – Link Management, Branding, Tracking & Sharing Plugin < 1.5.6 - Reflected Cross-Site Scripting

medium

Pretty-Link WordPress plugin 1.5.2 has XSS via url parameter.

CVSS:
6.1
Affected:
up to 1.5.6
Fixed in:
1.5.6
Disclosed:
Dec 4, 2011

CVE-2011-4595 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database