VYPR

Permalink Manager Lite

by WordPress

CVEs (1)

  • CVE-2026-8494Jun 17, 2026
    risk 0.00cvss epss

    The Permalink Manager Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in the admin URI Editor interface in all versions up to, and including, 2.5.3.3 due to insufficient output escaping. This makes it possible for authenticated attackers,…