Maciej Bis Vulnerabilities and Affected Products
Vulnerabilities associated with Permalink Manager Lite.
Products
Clear product- Permalink Manager Lite6 vulnerabilities
- Permalink Manager Pro1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-32413MEDIUM | WordPress Permalink Manager Lite plugin < 2.5.3 - Broken Access Control vulnerabilityMissing Authorization vulnerability in Maciej Bis Permalink Manager Lite permalink-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Permalink Manager Lite: from n/a through < 2.5.3. CWE-862Mar 13, 2026 | CVSS5.3v3.1 | EPSS0.199% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-59010HIGH | WordPress Permalink Manager Lite Plugin <= 2.5.1.3 - Sensitive Data Exposure VulnerabilityInsertion of Sensitive Information Into Sent Data vulnerability in Maciej Bis Permalink Manager Lite permalink-manager allows Retrieve Embedded Sensitive Data.This issue affects Permalink Manager Lite: from n/a through <= 2.5.1.3. CWE-201Sep 26, 2025 | CVSS7.5v3.1 | EPSS0.359% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-37257HIGH | WordPress Permalink Manager Lite plugin <= 2.4.3.3 - Reflected Cross Site Scripting (XSS) vulnerabilityImproper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Maciej Bis Permalink Manager Lite allows Reflected XSS.This issue affects Permalink Manager Lite: from n/a through 2.4.3.3. CWE-79Jul 22, 2024 | CVSS7.1v3.1 | EPSS0.308% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-29092HIGH | WordPress Permalink Manager Lite plugin <= 2.4.3 - Reflected Cross Site Scripting (XSS) vulnerabilityImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Maciej Bis Permalink Manager Lite allows Reflected XSS.This issue affects Permalink Manager Lite: from n/a through 2.4.3. CWE-79Mar 19, 2024 | CVSS7.1v3.1 | EPSS0.398% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-41781MEDIUM | WordPress Permalink Manager Lite plugin <= 2.2.20 - Broken Access Control vulnerabilityBroken Access Control vulnerability in Permalink Manager Lite plugin <= 2.2.20 on WordPress. CWE-264Nov 18, 2022 | CVSS6.5v3.1 | EPSS0.649% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-0201MEDIUM | Permalink Manager < 2.2.15 - Reflected Cross-Site ScriptingThe Permalink Manager Lite WordPress plugin before 2.2.15 and Permalink Manager Pro WordPress plugin before 2.2.15 do not sanitise and escape query parameters before outputting them back in the debug page, leading to a Reflected Cross-Site Scripting issue | CVSS6.1v3.1 | EPSS3.37% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |