PT-2024-20908 · WordPress · Permalink Manager Lite

Muhammad Zeeshan

+1

·

Published

2024-03-19

·

Updated

2025-02-05

·

CVE-2024-2538

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Permalink Manager Lite plugin for WordPress versions up to, and including, 2.4.3.1
Description The issue arises from a missing capability check on the ajax save permalink function, allowing authenticated attackers with author access or above to modify the permalinks of arbitrary posts. This enables unauthorized modification of data.
Recommendations For Permalink Manager Lite plugin for WordPress versions up to, and including, 2.4.3.1, consider disabling the ajax save permalink function until a patch is available to prevent unauthorized modification of permalinks. Restrict access to the plugin's functionality to minimize the risk of exploitation, especially for users with author access and above.

Exploit

Fix

IDOR

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-2538

Affected Products

Permalink Manager Lite