Cross-site Scripting Vulnerability in Pretty Link Lite Plugin for WordPress
CVE-2011-5191

Currently unrated

Key Information:

Vendor

Wordpress

Vendor
CVE Published:
23 September 2012

What is CVE-2011-5191?

The Pretty Link Lite plugin for WordPress is susceptible to a cross-site scripting (XSS) vulnerability, allowing remote attackers to inject arbitrary web scripts or HTML into the application. This occurs through the manipulation of the slug parameter in pretty-bar.php. If exploited, this vulnerability can lead to unauthorized actions on behalf of users, data theft, or compromise of site integrity. Users are urged to upgrade to version 1.5.4 or later to mitigate this risk.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.