CVE-2025-48247: WordPress Shortlinks by Pretty Links plugin <= 3.6.15 - Broken Access Control Vulnerability
Missing Authorization vulnerability in Blair Williams Shortlinks by Pretty Links allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Shortlinks by Pretty Links: from n/a through 3.6.15.
Other sources
Missing Authorization vulnerability in Blair Williams Shortlinks by Pretty Links pretty-link allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Shortlinks by Pretty Links: from n/a through <= 3.6.15.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48247?
CVE-2025-48247 has a high severity level due to the potential for unauthorized access and manipulation of resources.
How do I fix CVE-2025-48247?
To fix CVE-2025-48247, update Shortlinks by Pretty Links to version 3.6.16 or later where the vulnerability has been patched.
What systems are affected by CVE-2025-48247?
CVE-2025-48247 affects all versions of Shortlinks by Pretty Links from n/a up to and including 3.6.15.
What type of vulnerability is CVE-2025-48247?
CVE-2025-48247 is a Missing Authorization vulnerability related to incorrectly configured access control security levels.
How can I mitigate the risks associated with CVE-2025-48247?
To mitigate risks from CVE-2025-48247, ensure proper access control configurations and limit user permissions as necessary.