CVE-2025-59010
7.5Maciej Bis · Permalink Manager Lite
The Permalink Manager Lite plugin for WordPress is vulnerable to sensitive data exposure due to the improper insertion of sensitive information into sent data.
Executive summary
An unauthenticated sensitive data exposure vulnerability in the Permalink Manager Lite plugin allows remote attackers to retrieve embedded sensitive information from affected WordPress sites.
Vulnerability
This vulnerability, categorized as CWE-201, involves the insecure transmission of sensitive data by the plugin. The CVSS vector indicates that the attack requires no special privileges and can be performed remotely by an unauthenticated actor.
Business impact
The exploitation of this flaw can lead to the unauthorized disclosure of sensitive information, potentially compromising user data or internal system configurations. With a CVSS score of 7.5, this high-severity vulnerability poses a significant risk to data privacy and regulatory compliance. Organizations relying on this plugin for URL management may face reputational damage if sensitive data is exfiltrated by malicious actors.
Remediation
Immediate Action: Review the official vendor advisory for the release of a security patch and update the Permalink Manager Lite plugin to the latest version immediately upon availability.
Proactive Monitoring: Monitor server access logs for anomalous, high-frequency requests directed at endpoints associated with the Permalink Manager plugin.
Compensating Controls: Implement a Web Application Firewall (WAF) rule to filter or block suspicious requests targeting the plugin's data-handling endpoints until an official patch is deployed.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the high severity and the unauthenticated nature of this vulnerability, administrators should treat this as a priority update. If an immediate patch is not available, consider deactivating the plugin as a temporary measure to eliminate the attack surface until the vendor releases a secure version.
Sources
Originally found and disclosed by Que Thanh Tuan | Patchstack Bug Bounty Program, per the CVE Program record.