Cross-site Scripting Vulnerability in Pretty Link Lite Plugin for WordPress
CVE-2011-5191
Currently unrated
What is CVE-2011-5191?
The Pretty Link Lite plugin for WordPress is susceptible to a cross-site scripting (XSS) vulnerability, allowing remote attackers to inject arbitrary web scripts or HTML into the application. This occurs through the manipulation of the slug parameter in pretty-bar.php. If exploited, this vulnerability can lead to unauthorized actions on behalf of users, data theft, or compromise of site integrity. Users are urged to upgrade to version 1.5.4 or later to mitigate this risk.