VYPR

Permalink Manager Pro

by WordPress

CVEs (2)

  • CVE-2024-2738MedApr 9, 2024
    risk 0.40cvss 6.1epss 0.01

    The Permalink Manager Lite and Pro plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the ‘s’ parameter in multiple instances in all versions up to, and including, 2.4.3.1 due to insufficient input sanitization and output escaping. This makes it…

  • CVE-2022-0201MedFeb 14, 2022
    risk 0.40cvss 6.1epss 0.03

    The Permalink Manager Lite WordPress plugin before 2.2.15 and Permalink Manager Pro WordPress plugin before 2.2.15 do not sanitise and escape query parameters before outputting them back in the debug page, leading to a Reflected Cross-Site Scripting issue