{"error":0,"message":null,"data":{"name":"PrettyLinks \u2013 Affiliate Link Management, URL Shortener, Link Cloaking, Tracking &amp; Branded Short Links","plugin":"pretty-link","link":"https:\/\/wordpress.org\/plugins\/pretty-link\/","latest":"1787634900","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"ffc8239e15c7da7b6eec83973dabdea8e0d3994186a8fa6ca7d1450f2fedb289","name":"PrettyLinks \u2013 Affiliate Link Management, URL Shortener, Link Cloaking, Tracking &amp; Branded Short Links [pretty-link] < 1.6.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.6.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2015-9457","name":"CVE-2015-9457","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2015-9457","description":"[en] The pretty-link plugin before 1.6.8 for WordPress has PrliLinksController::list_links SQL injection via the group parameter.","date":"2019-10-10"},{"id":"560f87cc72eb40054dfbe73b7c53842ae25317ec","name":"Pretty Links \u2013 Link Management, Branding, Tracking & Sharing Plugin <= 1.6.7 - SQL Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/pretty-link\/pretty-links-link-management-branding-tracking-sharing-plugin-167-sql-injection","description":"The pretty-link plugin before 1.6.8 for WordPress has PrliLinksController::list_links SQL injection via the group parameter.","date":"2015-07-08"},{"id":"8575fe05-c470-4086-90d0-22b4d25d1c56","name":"Pretty Link Lite &lt;= 1.6.7 - Authenticated SQL Injection","link":"https:\/\/wpscan.com\/vulnerability\/8575fe05-c470-4086-90d0-22b4d25d1c56","description":"The Pretty Links &ndash; Link Management, Branding, Tracking &amp; Sharing Plugin WordPress plugin was affected by an Authenticated SQL Injection security vulnerability.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"h","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"7.2","severity":"h","exploitable":"1.2","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"7.2","severity":"high","av":"network","ac":"low","pr":"high","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"1.2","impact":"5.9"},"cwe":[{"cwe":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","description":"The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data."}]}},{"uuid":"abbca99a15846c145d34be5ea743c28c905a35cf41c0e3414a500e08928b38cd","name":"PrettyLinks \u2013 Affiliate Link Management, URL Shortener, Link Cloaking, Tracking &amp; Branded Short Links [pretty-link] < 1.6.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.6.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2013-1636","name":"CVE-2013-1636","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2013-1636","description":"[en] Cross-site scripting (XSS) vulnerability in open-flash-chart.swf in Open Flash Chart (aka Open-Flash Chart), as used in the Pretty Link Lite plugin before 1.6.3 for WordPress, JNews (com_jnews) component 8.0.1 for Joomla!, and CiviCRM 3.1.0 through 4.2.9 and 4.3.0 through 4.3.3, allows remote attackers to inject arbitrary web script or HTML via the get-data parameter.","date":"2014-03-12"},{"id":"b7e25846c53749ee66a19f306653ef39af4a79fd","name":"Pretty Links Lite < 1.6.3 - Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/pretty-link\/pretty-links-lite-163-stored-cross-site-scripting","description":"Cross-site scripting (XSS) vulnerability in open-flash-chart.swf in Open Flash Chart (aka Open-Flash Chart), as used in the Pretty Link Lite plugin before 1.6.3 for WordPress, JNews (com_jnews) component 8.0.1 for Joomla!, and CiviCRM 3.1.0 through 4.2.9 and 4.3.0 through 4.3.3, allows remote attackers to inject arbitrary web script or HTML via the get-data parameter.","date":"2014-08-01"},{"id":"b835dc19-0512-4902-8d60-fa1f90ef0bcb","name":"Pretty Link Lite &lt;= 1.6.2 - XSS in SWF","link":"https:\/\/wpscan.com\/vulnerability\/b835dc19-0512-4902-8d60-fa1f90ef0bcb","description":"The Pretty Links &ndash; Link Management, Branding, Tracking &amp; Sharing Plugin WordPress plugin was affected by a XSS in SWF security vulnerability.","date":null}],"impact":{"cvss":{"version":null,"vector":null,"av":null,"ac":null,"pr":null,"ui":null,"s":null,"c":null,"i":null,"a":null,"score":"0.0","severity":null,"exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"7ee8a2eeed144f2ef2a9a4b69f33a33438edd302418be2c88c5e7d337f8f7a8f","name":"PrettyLinks \u2013 Affiliate Link Management, URL Shortener, Link Cloaking, Tracking &amp; Branded Short Links [pretty-link] < 1.5.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.5.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2011-5191","name":"CVE-2011-5191","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2011-5191","description":"[en] Cross-site scripting (XSS) vulnerability in pretty-bar.php in Pretty Link Lite plugin before 1.5.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the slug parameter, a different vulnerability than CVE-2011-5192.","date":"2012-09-23"},{"id":"59fe55dd70c11b2327d5bf8a4cb65682b4343c16","name":"WordPress  Pretty Link Lite Plugin <= 1.5.3 - XSS","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/pretty-link\/vulnerability\/wordpress-pretty-link-lite-plugin-1-5-3-xss","description":"Because of this vulnerability in pretty-bar.php, the  attackers can inject arbitrary web script or HTML via the \"slug\" parameter.\nUpdate the plugin.","date":"2012-09-23"},{"id":"0d4a905fef8b775d1f3a4402ce1469252ff7a1bf","name":"Pretty Link Lite < 1.5.4 - Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/pretty-link-lite\/pretty-link-lite-154-cross-site-scripting","description":"Cross-site scripting (XSS) vulnerability in pretty-bar.php in Pretty Link Lite plugin before 1.5.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the slug parameter, a different vulnerability than CVE-2011-5192.","date":"2011-12-12"}],"impact":{"cvss":{"version":null,"vector":null,"av":null,"ac":null,"pr":null,"ui":null,"s":null,"c":null,"i":null,"a":null,"score":"0.0","severity":null,"exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"2ef324869417f871f1ce4f4797181a18e1c55eb08e5115856b8e31c2a091d665","name":"PrettyLinks \u2013 Affiliate Link Management, URL Shortener, Link Cloaking, Tracking &amp; Branded Short Links [pretty-link] < 1.5.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.5.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2011-5192","name":"CVE-2011-5192","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2011-5192","description":"[en] Cross-site scripting (XSS) vulnerability in pretty-bar.php in Pretty Link Lite plugin before 1.5.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the slug parameter, a different vulnerability than CVE-2011-5191.","date":"2012-09-23"},{"id":"b9a49783a0b814a79538dca192dcc36b97d656b4","name":"WordPress Pretty Link Lite Plugin <= 1.5.5 - XSS","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/pretty-link\/vulnerability\/wordpress-pretty-link-lite-plugin-1-5-5-xss","description":"Because of this vulnerability in pretty-bar.php, the attackers can inject arbitrary web script or HTML via the \"slug\" parameter.\nUpdate the plugin.","date":"2012-09-23"},{"id":"dbd6bdc35f5c80fbca5a68aed0eb81e2412a422a","name":"Pretty Link Lite < 1.5.6 - Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/pretty-link-lite\/pretty-link-lite-156-cross-site-scripting","description":"Cross-site scripting (XSS) vulnerability in pretty-bar.php in Pretty Link Lite plugin before 1.5.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the slug parameter, a different vulnerability than CVE-2011-5191.","date":"2012-01-06"}],"impact":{"cvss":{"version":null,"vector":null,"av":null,"ac":null,"pr":null,"ui":null,"s":null,"c":null,"i":null,"a":null,"score":"0.0","severity":null,"exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"7b4d5edc12030fc744ece71646e6a112cc9831f287b10e186e94931a256ac6a4","name":"PrettyLinks \u2013 Affiliate Link Management, URL Shortener, Link Cloaking, Tracking &amp; Branded Short Links [pretty-link] <= 1.4.56","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.4.56","max_operator":"le","unfixed":"0","closed":"0"},"source":[{"id":"8d726ace194500b2ef93ba7bf76914bfe71faef0","name":"WordPress Pretty Link Lite Plugin 1.4.56 - Multiple SQL Injection Vulnerabilities","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/pretty-link\/vulnerability\/wordpress-pretty-link-lite-plugin-1-4-56-multiple-sql-injection-vulnerabilities","description":"This WordPress  Pretty Link Lite plugin is prone to an SQL injection. This vulnerability allows  an attacker to modify data, compromise the access and application or exploit hidden vulnerabilities in the underlying database.","date":"2011-06-27"}],"impact":[]},{"uuid":"cd158ec8dc3fca7026161032b95030bfa8e3a0abe23bb2b993a3d5de11557445","name":"PrettyLinks \u2013 Affiliate Link Management, URL Shortener, Link Cloaking, Tracking &amp; Branded Short Links [pretty-link] < 2.1.10","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.1.10","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"aaa7e76b8291d9b7bb2abd0106ee4dba0e32cea4","name":"WordPress Shortlinks by Pretty Links plugin <= 2.1.9 - Stored Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/pretty-link\/vulnerability\/wordpress-shortlinks-by-pretty-links-plugin-2-1-9-stored-cross-site-scripting-xss-vulnerability","description":"Stored Cross-Site Scripting (XSS) vulnerability found by Jerome Bruandet in WordPress Shortlinks by Pretty Links plugin (versions <= 2.1.9).","date":"2019-06-25"}],"impact":[]},{"uuid":"3b411390e17af4304d66ef84163432f46e5d4763189d4dbc451b9a74e94f27ee","name":"PrettyLinks \u2013 Affiliate Link Management, URL Shortener, Link Cloaking, Tracking &amp; Branded Short Links [pretty-link] < 2.1.10","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.1.10","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"4e68b105903b90077463b8e03878e9aac44974ed","name":"WordPress Shortlinks by Pretty Links plugin <= 2.1.9 - CSV injection vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/pretty-link\/vulnerability\/wordpress-shortlinks-by-pretty-links-plugin-2-1-9-csv-injection-vulnerability","description":"CSV injection vulnerability found by Jerome Bruandet in WordPress Shortlinks by Pretty Links plugin (versions <= 2.1.9).","date":"2019-06-25"}],"impact":[]},{"uuid":"5a8ad69abb3a557a017d99411ab0ca5abe710e7d031544bedbce6f2b8ebe00b0","name":"PrettyLinks \u2013 Affiliate Link Management, URL Shortener, Link Cloaking, Tracking &amp; Branded Short Links [pretty-link] < 1.6.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.6.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"27fe931782ba1a226cbecf9680e1f7331f6742e2","name":"WordPress Pretty Link Lite Plugin <= 1.6.0 - Cross Site Scripting","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/pretty-link\/vulnerability\/wordpress-pretty-link-lite-plugin-1-6-0-cross-site-scripting","description":"Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.\nUpgrade plugin.","date":"2016-07-07"}],"impact":[]},{"uuid":"02b17646f536c7110958b3069c0d91994a56dcdbddbf7fabe4b05b1bc9c8744b","name":"PrettyLinks \u2013 Affiliate Link Management, URL Shortener, Link Cloaking, Tracking &amp; Branded Short Links [pretty-link] < 1.6.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.6.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"077761c66631372ed6251258342a57b602a2e276","name":"WordPress Pretty Link Lite Plugin <= 1.6.7 - SQL Injection","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/pretty-link\/vulnerability\/wordpress-pretty-link-lite-plugin-1-6-7-sql-injection","description":"Because of this vulnerability, remote authenticated users can execute arbitrary SQL commands.\nUpgrade the plugin.","date":"2015-11-22"}],"impact":[]},{"uuid":"aa51a90df06b31fb1cde4ab88fa040f32d43e379b27e6de62a447dddd4300f2b","name":"PrettyLinks \u2013 Affiliate Link Management, URL Shortener, Link Cloaking, Tracking &amp; Branded Short Links [pretty-link] < 1.4.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.4.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"4ccab216452d83fe564dc0ad753fb4c27e40226b","name":"WordPress Pretty Link Plugin 1.4.56 - Multiple Cross Site Scripting Vulnerabilities","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/pretty-link\/vulnerability\/wordpress-pretty-link-plugin-1-4-56-multiple-cross-site-scripting-vulnerabilities","description":"WordPress Pretty Link plugin is prone to multiple cross-site scripting vulnerabilities that fail to properly clean up user-supplied input.  An attacker may execute arbitrary script code in the browser of an user in the context of the affected site. In this way the attacker can steal cookie-based authentication credentials.  Other attacks are also possible.\nUpdate the plugin.","date":"2011-10-13"}],"impact":[]},{"uuid":"1720003a5e0d66de344494affb723cf05fb653cece93a4befe110741dc84889f","name":"PrettyLinks \u2013 Affiliate Link Management, URL Shortener, Link Cloaking, Tracking &amp; Branded Short Links [pretty-link] < 1.5.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.5.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"fd831c3cb8269f2362a8eed744eb7f2c95465201","name":"WordPress Pretty Link Lite Plugin 1.5.2 - SQL Injection and Cross Site Scripting Vulnerabilities","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/pretty-link\/vulnerability\/wordpress-pretty-link-lite-plugin-1-5-2-sql-injection-and-cross-site-scripting-vulnerabilities","description":"Pretty Link Lite plugin is prone to multiple cross-site scripting and SQL-injection vulnerabilities because of failure to properly clean up user-supplied input. It allows an attacker to steal cookie-based authentication credentials, access or modify data, compromise the application or exploit latent vulnerabilities in the underlying database.\nUpdate the plugin.","date":"2012-05-15"}],"impact":[]},{"uuid":"e1ec21646c2ebc2cfaed9725504905c695cab636d37c3baf596b1cd620405221","name":"PrettyLinks \u2013 Affiliate Link Management, URL Shortener, Link Cloaking, Tracking &amp; Branded Short Links [pretty-link] < 1.6.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.6.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"1d9f45543039d792ad8ca6d8d9d1b0638b436b5e","name":"WordPress Pretty Link Plugin <= 1.6.3 -  Cross Site Scripting","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/pretty-link\/vulnerability\/wordpress-pretty-link-plugin-1-6-3-cross-site-scripting","description":"WordPress Pretty Link is prone to a cross-site scripting vulnerability.  It fails to properly clean up user-supplied input.  An attacker may execute arbitrary script code in the browser of an user in the context of the affected site. In this way the attacker can steal cookie-based authentication credentials.  Other attacks are also possible.\nUpdate the plugin.","date":"2013-02-20"}],"impact":[]},{"uuid":"ebf6ba599f6fe52e5caf4d639df69fea056007aedf51aea597ca10b1f619f1de","name":"PrettyLinks \u2013 Affiliate Link Management, URL Shortener, Link Cloaking, Tracking &amp; Branded Short Links [pretty-link] < 3.4.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.4.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-47149","name":"CVE-2022-47149","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-47149","description":"[en] Cross-Site Request Forgery (CSRF) vulnerability in Pretty Links plugin <=\u00a03.4.0 versions.","date":"2023-05-25"},{"id":"e84e9274a21e751e6291f2d8f048452ffe1f8a75","name":"WordPress  Shortlinks by Pretty Links Plugin  <= 3.4.0 is vulnerable to Cross Site Request Forgery (CSRF)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/pretty-link\/vulnerability\/wordpress-pretty-links-affiliate-links-link-branding-link-tracking-marketing-plugin-plugin-3-4-0-cross-site-request-forgery-csrf","description":"Update the WordPress Shortlinks by Pretty Links plugin to the latest available version (at least 3.4.1).\nMuhammad Daffa discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Shortlinks by Pretty Links Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. This vulnerability has been fixed in version 3.4.1.","date":"2023-04-13"},{"id":"17e583556049d0edf612d83c274508b85692cee7","name":"Shortlinks by Pretty Links <= 3.4.0 - Cross-Site Request Forgery via route","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/pretty-link\/shortlinks-by-pretty-links-340-cross-site-request-forgery-via-route","description":"The Shortlinks by Pretty Links plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4.0. This is due to missing or incorrect nonce validation on the route function. This makes it possible for unauthenticated attackers to clear link visit stats via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2023-04-13"},{"id":"3b8c9728-49a6-410e-9f30-e790dd994bc9","name":"Shortlinks by Pretty Links &lt; 3.4.1 - Link Visit Stats Clear via CSRF","link":"https:\/\/wpscan.com\/vulnerability\/3b8c9728-49a6-410e-9f30-e790dd994bc9","description":"The plugin does not have CSRF checks when clearing the Link Visits statistics, which could allow attackers to make logged in admins perform such actions via a CSRF attack","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:N\/A:L","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"n","i":"n","a":"l","score":"4.3","severity":"m","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:N\/A:L","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"none","i":"none","a":"low","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"98c6dac8e7bc48d36842b55805cf735dc39a03cf3ed87566719afeb764e48ee2","name":"PrettyLinks \u2013 Affiliate Link Management, URL Shortener, Link Cloaking, Tracking &amp; Branded Short Links [pretty-link] < 2.1.10","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.1.10","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2019-25147","name":"CVE-2019-25147","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2019-25147","description":"[en] The Pretty Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting via various IP headers as well as the referer header in versions up to, and including, 2.1.9 due to insufficient input sanitization and output escaping in the track_link function. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2023-06-07"},{"id":"ec3fa6c9754b2fa89efb228c56f1220f54d4efd3","name":"Pretty Links <= 2.1.9 - Unauthenticated Stored Cross-Site Scripting via track_link","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/pretty-link\/pretty-links-219-unauthenticated-stored-cross-site-scripting-via-track-link","description":"The Pretty Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting via various IP headers as well as the referer header in versions up to, and including, 2.1.9 due to insufficient input sanitization and output escaping in the track_link function. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2019-06-19"},{"id":"fae257da-dd57-4da7-a926-ecdbd52624c2","name":"Shortlinks by Pretty Links &lt;= 2.1.9 - Stored XSS and CSV Injection","link":"https:\/\/wpscan.com\/vulnerability\/fae257da-dd57-4da7-a926-ecdbd52624c2","description":"Details in the reference","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"7.2","severity":"h","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"7.2","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"7f4afbf03d70980f72e3e5da4d9bc0a8de4c2e847a2009d283dd807511a3426f","name":"PrettyLinks \u2013 Affiliate Link Management, URL Shortener, Link Cloaking, Tracking &amp; Branded Short Links [pretty-link] < 1.6.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.6.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"4c786353-9781-415b-938b-43d17dd45bbc","name":"Pretty Link Lite &lt;= 1.6.0 - Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/4c786353-9781-415b-938b-43d17dd45bbc","description":"The Pretty Links &ndash; Link Management, Branding, Tracking &amp; Sharing Plugin WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.","date":null}],"impact":[]},{"uuid":"832cd24331904b351997ccbd7e68edd09268034024cb346a3d39b4c1c8b3799a","name":"PrettyLinks \u2013 Affiliate Link Management, URL Shortener, Link Cloaking, Tracking &amp; Branded Short Links [pretty-link] < 3.6.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.6.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-2326","name":"CVE-2024-2326","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-2326","description":"[en] The Pretty Links \u2013 Affiliate Links, Link Branding, Link Tracking & Marketing Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.3. This is due to missing or incorrect nonce validation when saving plugin settings. This makes it possible for unauthenticated attackers to change the plugin's configuration including stripe integration via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2024-03-23"},{"id":"e2c61e62954a74fb27b3596cdf4575283b343ec0","name":"Pretty Links \u2013 Affiliate Links, Link Branding, Link Tracking & Marketing Plugin <= 3.6.3 - Cross-Site Request Forgery to Plugin Settings Update","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/pretty-link\/pretty-links-affiliate-links-link-branding-link-tracking-marketing-plugin-363-cross-site-request-forgery-to-plugin-settings-update","description":"The Pretty Links \u2013 Affiliate Links, Link Branding, Link Tracking & Marketing Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.3. This is due to missing or incorrect nonce validation when saving plugin settings. This makes it possible for unauthenticated attackers to change the plugin's configuration including stripe integration via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2024-03-22"},{"id":"911668cc7e606a773d27c65e27db3e7b292807a2","name":"WordPress  Shortlinks by Pretty Links Plugin    <= 3.6.3 is vulnerable to Cross Site Request Forgery (CSRF)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/pretty-link\/vulnerability\/wordpress-pretty-links-plugin-3-6-3-cross-site-request-forgery-to-plugin-settings-update-vulnerability","description":"Update the WordPress Shortlinks by Pretty Links plugin to the latest available version (at least 3.6.4).\nWebbernaut discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Shortlinks by Pretty Links Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. This vulnerability has been fixed in version 3.6.4.\nHave additional information or questions about this entry? Get in touch.","date":null},{"id":"64917099-3668-4857-8c2d-1762bbdbf29c","name":"Pretty Links &ndash; Affiliate Links, Link Branding, Link Tracking &amp; Marketing &lt; 3.6.4 - Plugin Settings Update via CSRF","link":"https:\/\/wpscan.com\/vulnerability\/64917099-3668-4857-8c2d-1762bbdbf29c","description":"The Pretty Links &ndash; Affiliate Links, Link Branding, Link Tracking &amp; Marketing Plugin  is vulnerable to Cross-Site Request Forgery. This is due to missing or incorrect nonce validation when saving plugin settings. This makes it possible for unauthenticated attackers to change the plugin&#039;s configuration including stripe integration via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"2.8","impact":"1.4"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"624f1b529d6bf8d07f3ec780c82c1f03d4dd0482ece05d9312330e46bd7f9ec6","name":"PrettyLinks \u2013 Affiliate Link Management, URL Shortener, Link Cloaking, Tracking &amp; Branded Short Links [pretty-link] < 3.6.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.6.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-29770","name":"CVE-2024-29770","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-29770","description":"[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pretty Links Shortlinks by Pretty Links allows Reflected XSS.This issue affects Shortlinks by Pretty Links: from n\/a through 3.6.2.","date":"2024-03-27"},{"id":"9657ae46e798ad3c7f4d7b79bcb423ae829dda14","name":"Shortlinks by Pretty Links <= 3.6.2 - Reflected Cross-Site Scripting via post_status","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/pretty-link\/shortlinks-by-pretty-links-362-reflected-cross-site-scripting-via-post-status","description":"The Shortlinks by Pretty Links plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the \u2018post_status\u2019 parameter in versions up to, and including, 3.6.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"2024-03-25"},{"id":"620758360f845a1ed9145777414d86834ee1b783","name":"WordPress  Shortlinks by Pretty Links Plugin    <= 3.6.2 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/pretty-link\/vulnerability\/wordpress-pretty-links-plugin-3-6-2-reflected-cross-site-scripting-xss-vulnerability","description":"Update the WordPress Shortlinks by Pretty Links plugin to the latest available version (at least 3.6.3).\nRafie Muhammad (Patchstack) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Shortlinks by Pretty Links Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 3.6.3.\nThis vulnerability was reported to and published by Patchstack. Our users receive alerts and protections up to 48 hours in advance.\nHave additional information or questions about this entry? Get in touch.","date":null},{"id":"abc61dbb-e117-45ac-8050-5ee511bd41fc","name":"Shortlinks by Pretty Links &lt; 3.6.3 - Reflected Cross-Site Scripting via post_status","link":"https:\/\/wpscan.com\/vulnerability\/abc61dbb-e117-45ac-8050-5ee511bd41fc","description":"The plugin does not sanitise and escape the post_status parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"7.1","severity":"h","exploitable":"2.8","impact":"3.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:L","score":"7.1","severity":"high","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"low","exploitable":"2.8","impact":"3.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"21866a380833a8bec0166b1f89fd61245c4b6e0d07d3c12305173cbb36db2560","name":"PrettyLinks \u2013 Affiliate Link Management, URL Shortener, Link Cloaking, Tracking &amp; Branded Short Links [pretty-link] < 3.6.16","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.6.16","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-48247","name":"CVE-2025-48247","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-48247","description":"[en] Missing Authorization vulnerability in Blair Williams Shortlinks by Pretty Links allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Shortlinks by Pretty Links: from n\/a through 3.6.15.","date":"2025-05-19"},{"id":"f8f6b91dcef51b1acd666562eb33844414083cdb","name":"WordPress Shortlinks by Pretty Links Plugin <= 3.6.15 is vulnerable to Broken Access Control","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/pretty-link\/vulnerability\/wordpress-shortlinks-by-pretty-links-3-6-15-broken-access-control-vulnerability","description":"<p>WordPress Shortlinks by Pretty Links Plugin <= 3.6.15 is vulnerable to Broken Access Control<\/p><p>Software: Shortlinks by Pretty Links<\/p><p>Fixed in version 3.6.16 <\/p><p>Affected Version <= 3.6.15<\/p><p>CVE: CVE-2025-48247<\/p>","date":"2025-05-19"},{"id":"76f1749496978601553128be2d8e65d6015f6840","name":"Shortlinks by Pretty Links <= 3.6.15 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/pretty-link\/shortlinks-by-pretty-links-3615-missing-authorization","description":"The PrettyLinks \u2013 Affiliate Links, Link Branding, Link Tracking, Marketing and Stripe Payments Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the search_results() function in all versions up to, and including, 3.6.15. This makes it possible for authenticated attackers, with Subscriber-level access and above, to search link statuses.","date":"2025-05-19"},{"id":"EUVD-2025-28167","name":"EUVD-2025-28167","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-28167","description":"Missing Authorization vulnerability in Blair Williams Shortlinks by Pretty Links allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Shortlinks by Pretty Links: from n\/a through 3.6.15.","date":"2025-05-19"}],"impact":{"cvss":{"version":null,"vector":null,"av":null,"ac":null,"pr":null,"ui":null,"s":null,"c":null,"i":null,"a":null,"score":"0.0","severity":null,"exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":null,"impact":null},"epss":"0.001"}},{"uuid":"a593f1a5c122801cfe18062e77791acfe2f2d09f644297c370bb6337036254b0","name":"PrettyLinks \u2013 Affiliate Link Management, URL Shortener, Link Cloaking, Tracking &amp; Branded Short Links [pretty-link] < 3.6.21","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.6.21","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-5062","name":"CVE-2026-5062","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-5062","description":"[en] The PrettyLinks \u2013 Affiliate Links, Link Branding, Link Tracking, Marketing and Stripe Payments Plugin plugin for WordPress is vulnerable to SQL Injection via the 's' (search) parameter on the Pretty Links listing page in all versions up to, and including, 3.6.20. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query in the `search_links_table()` function. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"2026-08-05"},{"id":"ccd7893f14dc6181e9b4f6f96d8016b2e93108a6","name":"PrettyLinks <= 3.6.20 - Authenticated (Administrator+) SQL Injection via 's' Parameter","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/pretty-link\/prettylinks-3620-authenticated-administrator-sql-injection-via-s-parameter","description":"The PrettyLinks \u2013 Affiliate Links, Link Branding, Link Tracking, Marketing and Stripe Payments Plugin plugin for WordPress is vulnerable to SQL Injection via the 's' (search) parameter on the Pretty Links listing page in all versions up to, and including, 3.6.20. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query in the `search_links_table()` function. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"2026-08-04"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"h","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"4.9","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"4.9","severity":"medium","av":"network","ac":"low","pr":"high","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","description":"The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}}]},"updated":"1785910239"}