SQL Injection Vulnerability in PrettyLinks Plugin for WordPress
CVE-2026-5062

4.9MEDIUM

What is CVE-2026-5062?

The PrettyLinks Plugin for WordPress is susceptible to SQL Injection through the 's' parameter on the listing page, affecting all versions up to 3.6.20. This vulnerability arises from inadequate escaping of user-supplied input and insufficient preparation of the SQL query in the search_links_table function. Authenticated attackers with Administrator-level access can exploit this flaw to insert malicious SQL queries, enabling them to retrieve sensitive information from the database, thus compromising the security of the application and its data integrity.

Affected Version(s)

PrettyLinks – Affiliate Link Management, URL Shortener, Link Cloaking, Tracking & Branded Short Links 0 <= 3.6.20

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Michael Iden (Mickhat)
.