cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forpermalink-manager permalink-manager

Direction: ascending
Jun 07, 2024

Permalink Manager Lite # CVE-2021-24769

CVE, Research URL

CVE-2021-24769

Date
Oct 25, 2021
Research Description
The Permalink Manager Lite WordPress plugin before 2.2.13.1 does not validate and escape the orderby parameter before using it in a SQL statement in the Permalink Manager page, leading to a SQL Injection
Affected versions
max 2.2.15.
Status
vulnerable

Permalink Manager Lite # CVE-2024-29092

CVE, Research URL

CVE-2024-29092

Date
Mar 19, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Maciej Bis Permalink Manager Lite allows Reflected XSS.This issue affects Permalink Manager Lite: from n/a through 2.4.3.
Affected versions
max 2.4.3.1.
Status
vulnerable

Permalink Manager Lite # CVE-2024-2543

CVE, Research URL

CVE-2024-2543

Date
Apr 10, 2024
Research Description
The Permalink Manager Lite plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_uri_editor' function in all versions up to, and including, 2.4.3.1. This makes it possible for unauthenticated attackers to view the permalinks of all posts.
Affected versions
max 2.4.3.2.
Status
vulnerable

Permalink Manager Lite # CVE-2024-2738

CVE, Research URL

CVE-2024-2738

Date
Apr 10, 2024
Research Description
The Permalink Manager Lite and Pro plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the ‘s’ parameter in multiple instances in all versions up to, and including, 2.4.3.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected versions
max 2.4.3.2.
Status
vulnerable

Permalink Manager Lite # CVE-2022-41781

CVE, Research URL

CVE-2022-41781

Date
Nov 19, 2022
Research Description
Broken Access Control vulnerability in Permalink Manager Lite plugin <= 2.2.20 on WordPress.
Affected versions
max 2.2.20.1.
Status
vulnerable

Permalink Manager Lite # CVE-2022-4410

CVE, Research URL

CVE-2022-4410

Date
Dec 15, 2022
Research Description
The Permalink Manager Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including 2.2.20.3 due to improper output escaping on post/page/media titles. This makes it possible for attackers to inject arbitrary web scripts on the permalink-manager page if another plugin or theme is installed on the site that allows lower privileged users with unfiltered_html the ability to modify post/page titles with malicious web scripts.
Affected versions
max 2.3.0.
Status
vulnerable

Permalink Manager Lite # CVE-2022-0201

CVE, Research URL

CVE-2022-0201

Date
Feb 14, 2022
Research Description
The Permalink Manager Lite WordPress plugin before 2.2.15 and Permalink Manager Pro WordPress plugin before 2.2.15 do not sanitise and escape query parameters before outputting them back in the debug page, leading to a Reflected Cross-Site Scripting issue
Affected versions
max 2.2.15.
Status
vulnerable

Permalink Manager Lite # CVE-2024-2538

CVE, Research URL

CVE-2024-2538

Date
Mar 20, 2024
Research Description
The Permalink Manager Lite plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ajax_save_permalink' function in all versions up to, and including, 2.4.3.1. This makes it possible for authenticated attackers, with author access and above, to modify the permalinks of arbitrary posts.
Affected versions
max 2.4.3.2.
Status
vulnerable

Permalink Manager Lite # CVE-2022-4021

CVE, Research URL

CVE-2022-4021

Date
Nov 16, 2022
Research Description
The Permalink Manager Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.2.20.1. This is due to missing or incorrect nonce validation on the extra_actions function. This makes it possible for unauthenticated attackers to change plugin settings including permalinks and site maps, via forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected versions
max 2.2.20.2.
Status
vulnerable
Jun 30, 2024

Permalink Manager Lite # CVE-2024-37257

CVE, Research URL

CVE-2024-37257

Date
Jul 22, 2024
Research Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Maciej Bis Permalink Manager Lite allows Reflected XSS.This issue affects Permalink Manager Lite: from n/a through 2.4.3.3.
Affected versions
max 2.4.3.4.
Status
vulnerable
Aug 29, 2024

Permalink Manager Lite # CVE-2024-8195

CVE, Research URL

CVE-2024-8195

Date
Aug 28, 2024
Research Description
The Permalink Manager Lite plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'debug_data', 'debug_query', and 'debug_redirect' functions in all versions up to, and including, 2.4.4. This makes it possible for unauthenticated attackers to extract sensitive data including password, title, and content of password-protected posts.
Affected versions
max 2.4.4.1.
Status
vulnerable
Oct 12, 2025

Permalink Manager Lite # CVE-2025-59010

CVE, Research URL

CVE-2025-59010

Date
Sep 26, 2025
Research Description
Insertion of Sensitive Information Into Sent Data vulnerability in Maciej Bis Permalink Manager Lite permalink-manager allows Retrieve Embedded Sensitive Data.This issue affects Permalink Manager Lite: from n/a through <= 2.5.1.3.
Affected versions
max 2.5.1.4.
Status
vulnerable
Apr 13, 2026

Permalink Manager Lite # CVE-2026-32413

CVE, Research URL

CVE-2026-32413

Date
Mar 14, 2026
Research Description
Missing Authorization vulnerability in Maciej Bis Permalink Manager Lite permalink-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Permalink Manager Lite: from n/a through < 2.5.3.
Affected versions
max 2.5.3.
Status
vulnerable
Jun 17, 2026

Permalink Manager Lite # CVE-2026-8494

CVE, Research URL

CVE-2026-8494

Date
-
Research Description
Permalink Manager Lite [permalink-manager] < 2.5.3.4 CVE-2026-8494
Affected versions
max 2.5.3.4.
Status
vulnerable