Known vulnerabilities in Permalink Manager Lite
Permalink Manager enhances WordPress’s built-in URL system, allowing you to change the URLs of native and custom post types and taxonomies.
7Reported vulnerabilities
9.8Highest CVSS score
2.6.0Latest version
100,000+Active installs
What to do now
Update Permalink Manager Lite to 2.5.3.4 or later.
7 of these have a fixed version available. Updating resolves them.
Reported vulnerabilities
| CVE | Severity | Exploit probability |
Affected versions | Fixed in | Published |
|---|---|---|---|---|---|
| CVE-2022-41781 | Critical | 0.7% | Before 2.2.20.1 | 2.2.20.1 |
November 18, 2022 |
| CVE-2026-8494 | Medium | 0.3% | 0 to 2.5.3.3 (inclusive) | 2.5.3.4 |
June 17, 2026 |
| CVE-2024-37257 | Medium | 0.3% | 2.4.3.3 and earlier | 2.4.3.4 |
June 27, 2024 |
| CVE-2024-29092 | Medium | 0.4% | 2.4.3 and earlier | 2.4.3.1 |
March 15, 2024 |
| CVE-2024-8195 | Medium | 0.5% | Before 2.4.4.1 | 2.4.4.1 |
August 28, 2024 |
| CVE-2026-32413 | Medium | 0.2% | Before 2.5.3 | 2.5.3 |
February 25, 2026 |
| CVE-2025-59010 | Medium | 0.4% | 2.5.1.3 and earlier | 2.5.1.4 |
September 6, 2025 |