Description
WordPress Plugin Shortlinks by Pretty Links-Best WordPress Link Tracking is prone to multiple cross-site scripting and SQL injection vulnerabilities because it fails to properly sanitize user-supplied input. Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. WordPress Plugin Shortlinks by Pretty Links-Best WordPress Link Tracking version 1.5.2 is vulnerable; other versions may also be affected.
Remediation
Update to the latest version
References
Related Vulnerabilities
WordPress Plugin Images to WebP Multiple Vulnerabilities (1.8)
EspoCRM Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2023-5965)
WordPress Plugin Gallery Master-Responsive Photo Galleries & Albums Cross-Site Scripting (1.0.22)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-3617)