Executive brief
The Permalink Manager Lite plugin for WordPress, which allows site owners to customize their website's URL structures, contains a security flaw. An attacker with basic contributor-level access can inject malicious scripts into post titles. These scripts will automatically run in the browser of any administrator who visits the plugin's management page, potentially allowing the attacker to perform unauthorized actions or compromise the site.
Technical details
The Permalink Manager Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient output escaping on post titles within the admin URI Editor interface. An authenticated attacker with Contributor-level permissions or higher can inject arbitrary web scripts into a post title. When an administrator subsequently accesses the Permalink Manager page, the malicious script executes within the context of their session. This is classified as a stored XSS vulnerability (CWE-79) and was addressed in version 2.5.3.4.
Affected products
- mbis Permalink Manager Lite up to, and including, 2.5.3.3
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory
References
- https://plugins.trac.wordpress.org/browser/permalink-manager/tags/2.5.3.1/includes/views/permalink-manager-uri-editor-post.php
- https://plugins.trac.wordpress.org/browser/permalink-manager/tags/2.5.3.3/includes/views/permalink-manager-uri-editor-post.php
- https://plugins.trac.wordpress.org/browser/permalink-manager/tags/2.5.3.4/includes/views/permalink-manager-uri-editor-post.php
- https://plugins.trac.wordpress.org/browser/permalink-manager/trunk/includes/views/permalink-manager-uri-editor-post.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/221c62a8-09c9-405a-bddf-06638437bd39?source=cve