Executive brief
BetterLinks is a popular WordPress plugin for creating and managing short URLs with cloaking and redirect capabilities. A flaw in the plugin allows authenticated users with basic subscriber-level access to create arbitrary short URLs with attacker-controlled targets, bypassing authorization checks. This enables attackers to launch phishing campaigns and manipulate search engine optimization (SEO), potentially damaging the site's reputation and exposing users to malicious redirects.
Technical details
The BetterLinks plugin fails to properly verify user authorization before allowing the creation of short URLs, a classic authorization bypass vulnerability. Exploitation requires both an authenticated user account (subscriber-level or higher) and the Fluent Boards companion plugin to be active. The vulnerability is facilitated by the betterlinks_admin_nonce being emitted globally on all frontend pages via wp_localize_script, making the nonce token accessible to any authenticated user rather than being restricted. An attacker can craft requests to create short URLs with arbitrary slugs and redirect destinations without appropriate permission checks. The vulnerability affects all versions up to and including 3.1.0; patches are presumed available in later versions.
Affected products
- Better Studio BetterLinks up to and including 3.1.0
Timeline
- 2026-08-25: disclosed