Description
WordPress Plugin Permalink Manager Lite is prone to a cross-site request forgery vulnerability. Exploiting this issue may allow a remote attacker to perform certain administrative actions and gain unauthorized access to the affected application; other attacks are also possible. WordPress Plugin Permalink Manager Lite version 2.2.19.2 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.2.19.3 or latest
References
Related Vulnerabilities
phpMyAdmin Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2013-3239)
WordPress Plugin wpForo Forum SQL Injection (1.4.9)
Joomla! Core 2.5.x Cross-Site Scripting (2.5.0 - 2.5.3)
PostgreSQL Other Vulnerability (CVE-2005-1410)
WordPress Plugin Very Simple Quiz Cross-Site Scripting (1.0.0)