What the vulnerability does
01Description
Broken Access Control vulnerability in Permalink Manager Lite plugin <= 2.2.20 on WordPress.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Broken Access Control vulnerability in Permalink Manager Lite plugin <= 2.2.20 on WordPress.
Explanation of Vulnerability in Simple Terms
Permalink Manager Lite version 2.2.20 and earlier contains a vulnerability that allows an attacker to modify site content and disrupt service without authentication. The flaw stems from insufficient access controls on core functionality. Site administrators should update to a version newer than 2.2.20 immediately.
What an attacker can do
Modify site content and cause service disruption without logging in.
Potential impact on your site
Attackers can alter permalinks and content availability, potentially breaking site navigation and SEO.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities