WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in PrettyLinks – Affiliate Link Management, URL Shortener, Link Cloaking, Tracking & Branded Short Links

🌠 Shorten, brand, and track any URL on your own domain. Keep your links — and your data — where they belong. 🔗

10Reported vulnerabilities
7.2Highest CVSS score
4.0.15Latest version
200,000+Active installs

What to do now

Update PrettyLinks – Affiliate Link Management, URL Shortener, Link Cloaking, Tracking & Branded Short Links to 3.6.21 or later. 10 of these have a fixed version available. Updating resolves them.

Plugin last updated: August 5, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2015-9457 High 7.2 1.9% Before 1.6.8 1.6.8 October 10, 2019
CVE-2013-1636 Medium 4.3 6.3% Before 1.6.3 1.6.3 March 12, 2014
CVE-2011-5192 Medium 4.3 2.1% Before 1.5.6 1.5.6 September 23, 2012
CVE-2011-5191 Medium 4.3 1.7% Before 1.5.4 1.5.4 September 23, 2012
CVE-2011-4595 Medium 6.1 2.4% Before 1.5.6 1.5.6 December 4, 2011
CVE-2024-29770 Medium 6.1 0.4% 3.6.2 and earlier 3.6.3 March 25, 2024
CVE-2026-5062 Medium 4.9 0.3% 0 to 3.6.20 (inclusive) 3.6.21 August 5, 2026
CVE-2025-48247 Medium 4.3 0.3% 3.6.15 and earlier 3.6.16 May 19, 2025
CVE-2024-2326 Medium 4.3 0.2% 3.6.3 and earlier 3.6.4 March 22, 2024
CVE-2022-47149 Medium 4.3 0.3% 3.4.0 and earlier 3.4.1 April 13, 2023

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.