PrettyLinks <= 3.6.20 - Authenticated (Administrator+) SQL Injection via 's' Parameter
medium
The PrettyLinks – Affiliate Links, Link Branding, Link Tracking, Marketing and Stripe Payments Plugin plugin for WordPress is vulnerable to SQL Injection via the 's' (search) parameter on the Pretty Links listing page in all versions up to, and including, 3.6.20. This is due to insufficient escaping on the user supplie...
- CVSS:
- 4.9
- Affected:
- up to 3.6.20
- Fixed in:
- 3.6.21
- Disclosed:
- Aug 4, 2026
CVE-2026-5062 on NVD →
Shortlinks by Pretty Links <= 3.6.15 - Missing Authorization
medium
The PrettyLinks – Affiliate Links, Link Branding, Link Tracking, Marketing and Stripe Payments Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the search_results() function in all versions up to, and including, 3.6.15. This makes it possible for authenticated attack...
- CVSS:
- 4.3
- Affected:
- up to 3.6.15
- Fixed in:
- 3.6.16
- Disclosed:
- May 19, 2025
CVE-2025-48247 on NVD →
Shortlinks by Pretty Links <= 3.6.2 - Reflected Cross-Site Scripting via post_status
medium
The Shortlinks by Pretty Links plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘post_status’ parameter in versions up to, and including, 3.6.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in...
- CVSS:
- 6.1
- Affected:
- up to 3.6.2
- Fixed in:
- 3.6.3
- Disclosed:
- Mar 25, 2024
CVE-2024-29770 on NVD →
Pretty Links – Affiliate Links, Link Branding, Link Tracking & Marketing Plugin <= 3.6.3 - Cross-Site Request Forgery to Plugin Settings Update
medium
The Pretty Links – Affiliate Links, Link Branding, Link Tracking & Marketing Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.3. This is due to missing or incorrect nonce validation when saving plugin settings. This makes it possible for unauthenticated a...
- CVSS:
- 4.3
- Affected:
- up to 3.6.3
- Fixed in:
- 3.6.4
- Disclosed:
- Mar 22, 2024
CVE-2024-2326 on NVD →
Shortlinks by Pretty Links <= 3.4.0 - Cross-Site Request Forgery via route
medium
The Shortlinks by Pretty Links plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4.0. This is due to missing or incorrect nonce validation on the route function. This makes it possible for unauthenticated attackers to clear link visit stats via a forged request granted...
- CVSS:
- 4.3
- Affected:
- up to 3.4.0
- Fixed in:
- 3.4.1
- Disclosed:
- Apr 13, 2023
CVE-2022-47149 on NVD →
Pretty Links <= 2.1.9 - Unauthenticated Stored Cross-Site Scripting via track_link
high
The Pretty Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting via various IP headers as well as the referer header in versions up to, and including, 2.1.9 due to insufficient input sanitization and output escaping in the track_link function. This makes it possible for unauthenticated attackers to i...
- CVSS:
- 7.2
- Affected:
- up to 2.1.10
- Fixed in:
- 2.1.10
- Disclosed:
- Jun 19, 2019
CVE-2019-25147 on NVD →
Pretty Links – Link Management, Branding, Tracking & Sharing Plugin <= 1.6.7 - SQL Injection
high
The pretty-link plugin before 1.6.8 for WordPress has PrliLinksController::list_links SQL injection via the group parameter.
- CVSS:
- 7.2
- Affected:
- up to 1.6.8
- Fixed in:
- 1.6.8
- Disclosed:
- Jul 8, 2015
CVE-2015-9457 on NVD →
Pretty Links Lite < 1.6.3 - Stored Cross-Site Scripting
high
Cross-site scripting (XSS) vulnerability in open-flash-chart.swf in Open Flash Chart (aka Open-Flash Chart), as used in the Pretty Link Lite plugin before 1.6.3 for WordPress, JNews (com_jnews) component 8.0.1 for Joomla!, and CiviCRM 3.1.0 through 4.2.9 and 4.3.0 through 4.3.3, allows remote attackers to inject arbitr...
- CVSS:
- 7.2
- Affected:
- up to 1.6.3
- Fixed in:
- 1.6.3
- Disclosed:
- Aug 1, 2014
CVE-2013-1636 on NVD →
Pretty Links – Link Management, Branding, Tracking & Sharing Plugin < 1.5.6 - Reflected Cross-Site Scripting
medium
Pretty-Link WordPress plugin 1.5.2 has XSS via url parameter.
- CVSS:
- 6.1
- Affected:
- up to 1.5.6
- Fixed in:
- 1.5.6
- Disclosed:
- Dec 4, 2011
CVE-2011-4595 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database