Description
WordPress Plugin Shortlinks by Pretty Links-Best WordPress Link Tracking is prone to multiple cross-site scripting and SQL injection vulnerabilities because it fails to properly sanitize user-supplied input. Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. WordPress Plugin Shortlinks by Pretty Links-Best WordPress Link Tracking version 1.5.2 is vulnerable; other versions may also be affected.
Remediation
Update to the latest version
References
Related Vulnerabilities
WordPress Plugin Custom Website Data Cross-Site Request Forgery (1.2)
WordPress Plugin Htaccess by BestWebSoft Cross-Site Scripting (1.4)
MySQL CVE-2018-3283 Vulnerability (CVE-2018-3283)
OpenSSL Out-of-bounds Write Vulnerability (CVE-2025-69419)
Nginx Improper Certificate Validation Vulnerability (CVE-2009-3555)