Access violation vulnerability in PrettyLinks – Affiliate Links, Link Branding, Link Tracking, Marketing and Stripe Payments Plugin 3.6.15

The PrettyLinks plugin for WordPress, which helps with creating and tracking affiliate links, is at risk of being accessed without permission. The issue is caused by a missing security check in the search_results() function, which affects all versions up to 3.6.15. This means that attackers who are logged in and have at least Subscriber-level access can view the status of links.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.