Extension WordPress

Vulnérabilités PrettyLinks – Affiliate Link Management, URL Shortener, Link Cloaking, Tracking & Branded Short Links

Cette page rassemble les failles publiées pour PrettyLinks – Affiliate Link Management, URL Shortener, Link Cloaking, Tracking & Branded Short Links, leurs plages de versions affectées et les correctifs signalés dans la base locale.

8Vulnérabilités
0Critiques
8Avec correctif
7,2CVSS maximal

Historique de sécurité

CVE et vulnérabilités de PrettyLinks – Affiliate Link Management, URL Shortener, Link Cloaking, Tracking & Branded Short Links

8 fiches

CVE-2025-48247 Moyenne · 4,3
PrettyLinks – Affiliate Link Management, URL Shortener, Link Cloaking, Tracking & Branded Short Links

Shortlinks by Pretty Links <= 3.6.15 – Missing Authorization

The PrettyLinks – Affiliate Links, Link Branding, Link Tracking, Marketing and Stripe Payments Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the search_results() function in all versions up to, and…

Versions affectées

*-3.6.15

Correctif

3.6.16

Publication

19/05/2025

CVE-2024-29770 Moyenne · 6,1
PrettyLinks – Affiliate Link Management, URL Shortener, Link Cloaking, Tracking & Branded Short Links

Shortlinks by Pretty Links <= 3.6.2 – Reflected Cross-Site Scripting via post_status

The Shortlinks by Pretty Links plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘post_status’ parameter in versions up to, and including, 3.6.2 due to insufficient input sanitization and output escaping. This makes it possible for…

Versions affectées

*-3.6.2

Correctif

3.6.3

Publication

25/03/2024

CVE-2024-2326 Moyenne · 4,3
PrettyLinks – Affiliate Link Management, URL Shortener, Link Cloaking, Tracking & Branded Short Links

Pretty Links – Affiliate Links, Link Branding, Link Tracking & Marketing Plugin <= 3.6.3 – Cross-Site Request Forgery to Plugin Settings Update

The Pretty Links – Affiliate Links, Link Branding, Link Tracking & Marketing Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.3. This is due to missing or incorrect nonce…

Versions affectées

*-3.6.3

Correctif

3.6.4

Publication

22/03/2024

CVE-2022-47149 Moyenne · 4,3
PrettyLinks – Affiliate Link Management, URL Shortener, Link Cloaking, Tracking & Branded Short Links

Shortlinks by Pretty Links <= 3.4.0 – Cross-Site Request Forgery via route

The Shortlinks by Pretty Links plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4.0. This is due to missing or incorrect nonce validation on the route function. This makes it possible…

Versions affectées

*-3.4.0

Correctif

3.4.1

Publication

13/04/2023

CVE-2019-25147 Élevée · 7,2
PrettyLinks – Affiliate Link Management, URL Shortener, Link Cloaking, Tracking & Branded Short Links

Pretty Links <= 2.1.9 – Unauthenticated Stored Cross-Site Scripting via track_link

The Pretty Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting via various IP headers as well as the referer header in versions up to, and including, 2.1.9 due to insufficient input sanitization and output escaping in…

Versions affectées

[*, 2.1.10)

Correctif

2.1.10

Publication

19/06/2019

CVE-2013-1636 Élevée · 7,2
PrettyLinks – Affiliate Link Management, URL Shortener, Link Cloaking, Tracking & Branded Short Links

Pretty Links Lite < 1.6.3 – Stored Cross-Site Scripting

Cross-site scripting (XSS) vulnerability in open-flash-chart.swf in Open Flash Chart (aka Open-Flash Chart), as used in the Pretty Link Lite plugin before 1.6.3 for WordPress, JNews (com_jnews) component 8.0.1 for Joomla!, and CiviCRM 3.1.0 through 4.2.9 and 4.3.0…

Versions affectées

[*, 1.6.3)

Correctif

1.6.3

Publication

01/08/2014

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités