Extension WordPress
Vulnérabilités PrettyLinks – Affiliate Link Management, URL Shortener, Link Cloaking, Tracking & Branded Short Links
Cette page rassemble les failles publiées pour PrettyLinks – Affiliate Link Management, URL Shortener, Link Cloaking, Tracking & Branded Short Links, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de PrettyLinks – Affiliate Link Management, URL Shortener, Link Cloaking, Tracking & Branded Short Links
8 fiches
Shortlinks by Pretty Links <= 3.6.15 – Missing Authorization
The PrettyLinks – Affiliate Links, Link Branding, Link Tracking, Marketing and Stripe Payments Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the search_results() function in all versions up to, and…
*-3.6.15
3.6.16
19/05/2025
Shortlinks by Pretty Links <= 3.6.2 – Reflected Cross-Site Scripting via post_status
The Shortlinks by Pretty Links plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘post_status’ parameter in versions up to, and including, 3.6.2 due to insufficient input sanitization and output escaping. This makes it possible for…
*-3.6.2
3.6.3
25/03/2024
Pretty Links – Affiliate Links, Link Branding, Link Tracking & Marketing Plugin <= 3.6.3 – Cross-Site Request Forgery to Plugin Settings Update
The Pretty Links – Affiliate Links, Link Branding, Link Tracking & Marketing Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.3. This is due to missing or incorrect nonce…
*-3.6.3
3.6.4
22/03/2024
Shortlinks by Pretty Links <= 3.4.0 – Cross-Site Request Forgery via route
The Shortlinks by Pretty Links plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4.0. This is due to missing or incorrect nonce validation on the route function. This makes it possible…
*-3.4.0
3.4.1
13/04/2023
Pretty Links <= 2.1.9 – Unauthenticated Stored Cross-Site Scripting via track_link
The Pretty Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting via various IP headers as well as the referer header in versions up to, and including, 2.1.9 due to insufficient input sanitization and output escaping in…
[*, 2.1.10)
2.1.10
19/06/2019
Pretty Links – Link Management, Branding, Tracking & Sharing Plugin <= 1.6.7 – SQL Injection
The pretty-link plugin before 1.6.8 for WordPress has PrliLinksController::list_links SQL injection via the group parameter.
[*, 1.6.8)
1.6.8
08/07/2015
Pretty Links Lite < 1.6.3 – Stored Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in open-flash-chart.swf in Open Flash Chart (aka Open-Flash Chart), as used in the Pretty Link Lite plugin before 1.6.3 for WordPress, JNews (com_jnews) component 8.0.1 for Joomla!, and CiviCRM 3.1.0 through 4.2.9 and 4.3.0…
[*, 1.6.3)
1.6.3
01/08/2014
Pretty Links – Link Management, Branding, Tracking & Sharing Plugin < 1.5.6 – Reflected Cross-Site Scripting
Pretty-Link WordPress plugin 1.5.2 has XSS via url parameter.
[*, 1.5.6)
1.5.6
04/12/2011
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.