CVE-2026-5062: PrettyLinks <= 3.6.20 - Authenticated (Administrator+) SQL Injection via 's' Parameter
The PrettyLinks – Affiliate Links, Link Branding, Link Tracking, Marketing and Stripe Payments Plugin plugin for WordPress is vulnerable to SQL Injection via the 's' (search) parameter on the Pretty Links listing page in all versions up to, and including, 3.6.20. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query in the searchlinkstable() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5062?
CVE-2026-5062 has a medium severity rating of 4.9.
How do I fix CVE-2026-5062?
To fix CVE-2026-5062, update the PrettyLinks plugin to a version beyond 3.6.20.
What kind of vulnerability is CVE-2026-5062?
CVE-2026-5062 is an SQL Injection vulnerability.
Who is affected by CVE-2026-5062?
CVE-2026-5062 affects users with the PrettyLinks plugin version 3.6.20 and earlier.
How does CVE-2026-5062 impact the system?
CVE-2026-5062 allows authenticated users with Administrator privileges to execute SQL injection attacks.