CVE · Medium

CVE-2024-2326 — PrettyLinks – Affiliate Link Management, URL Shortener, Link Cloaking, Tracking & Branded Short Links [pretty-link] < 3.6.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-2326 PrettyLinks – Affiliate Link Management, URL Shortener, Link Cloaking, Tracking & Branded Short Links [pretty-link] < 3.6.4 Cross-Site Request Forgery (CSRF) Medium 4.3 < 3.6.4 3.6.4 2024-03-22

CVE-2024-2326

The Pretty Links plugin for WordPress contains a Cross-Site Request Forgery vulnerability affecting versions 3.6.3 and earlier that stems from inadequate nonce verification during settings updates. An attacker could exploit this by crafting a malicious request that modifies plugin configuration, including Stripe integration settings, if they convince an administrator to click a link. This flaw allows unauthenticated threat actors to alter sensitive plugin options without proper authorization checks.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.