Description
WordPress Plugin Shortlinks by Pretty Links-Best WordPress Link Tracking is prone to multiple cross-site scripting and SQL injection vulnerabilities because it fails to properly sanitize user-supplied input. Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. WordPress Plugin Shortlinks by Pretty Links-Best WordPress Link Tracking version 1.5.2 is vulnerable; other versions may also be affected.
Remediation
Update to the latest version
References
Related Vulnerabilities
MySQL CVE-2023-21982 Vulnerability (CVE-2023-21982)
PHP Server-Side Request Forgery (SSRF) Vulnerability (CVE-2017-7272)
Python Cryptographic Issues Vulnerability (CVE-2013-7040)
WordPress Plugin Slider by 10Web-Responsive Image Slider Unspecified Vulnerability (1.1.9)
WordPress Plugin Jigoshop-Store Toolkit Privilege Escalation (1.3.7)