The Permalink Manager Lite plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ajax_save_permalink' function in all versions up to, and including, 2.4.3.1. This makes it possible for authenticated attackers, with author access and above, to modify the permalinks of arbitrary posts.
Metrics
Affected Vendors & Products
References
History
Wed, 05 Feb 2025 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Permalink Manager Lite Project
Permalink Manager Lite Project permalink Manager Lite |
|
Weaknesses | CWE-862 | |
CPEs | cpe:2.3:a:permalink_manager_lite_project:permalink_manager_lite:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Permalink Manager Lite Project
Permalink Manager Lite Project permalink Manager Lite |

Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2024-08-05T19:30:44.931Z
Reserved: 2024-03-15T17:29:45.829Z
Link: CVE-2024-2538

Updated: 2024-08-01T19:18:48.233Z

Status : Analyzed
Published: 2024-03-20T06:15:12.423
Modified: 2025-02-05T18:15:22.620
Link: CVE-2024-2538

No data.