CVE · Medium

CVE-2022-47149 — PrettyLinks – Affiliate Link Management, URL Shortener, Link Cloaking, Tracking & Branded Short Links [pretty-link] < 3.4.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-47149 PrettyLinks – Affiliate Link Management, URL Shortener, Link Cloaking, Tracking & Branded Short Links [pretty-link] < 3.4.1 Cross-Site Request Forgery (CSRF) Medium 4.3 < 3.4.1 3.4.1 2023-04-13

CVE-2022-47149

The PrettyLinks plugin for WordPress versions prior to 3.4.1 contains a cross-site request forgery vulnerability that could be exploited by an attacker to trick authenticated users with elevated privileges into performing unintended actions on the site. The flaw was identified by Muhammad Daffa and allows malicious actors to leverage a user's existing session to execute requests without their knowledge or consent. The vulnerability has been patched in version 3.4.1 and users should upgrade immediately to address this security issue.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.