CVE · High

CVE-2023-45104 — BetterLinks – Link Shortener, Link Cloaking, Redirects, Affiliate Link Manager & MCP [betterlinks] < 1.6.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-45104 BetterLinks – Link Shortener, Link Cloaking, Redirects, Affiliate Link Manager & MCP [betterlinks] < 1.6.1 Missing Authorization High 7.3 < 1.6.1 1.6.1 2023-10-18

CVE-2023-45104

The BetterLinks plugin for WordPress contains a broken access control vulnerability in versions before 1.6.1 that was discovered by Nguyen Anh Tien. The flaw stems from insufficient authorization checks in certain functions, allowing unauthenticated or low-privileged users to perform actions that should be restricted to higher-privileged accounts. This issue has been patched in version 1.6.1 and users should update immediately.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.