← back to popular plugins
wordfence / plugin · permalink-manager

Permalink Manager Lite

permalink-manager
total installs
100,000
total vulns
2
critical
0
high
0
medium
2
low
0
latest vuln
patched
2
unpatched
0
avg time to patch
vulnerabilities (2)
Permalink Manager Lite < 2.5.3 - Missing Authorization
medium ✓ patched
cvss score 5.3
cwe CWE-862: Missing Authorization
published Feb 25, 2026
The Permalink Manager Lite plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to 2.5.3. This makes it possible for unauthenticated attackers to perform an unauthorized action.
Permalink Manager Lite <= 2.5.1.3 - Unauthenticated Sensitive Information Exposure
medium ✓ patched
cvss score 5.3
cwe CWE-201: Insertion of Sensitive Information Into Sent Data
published Sep 6, 2025
The Permalink Manager Lite plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.5.1.3. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.