PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-8494 mbis CVE debrief

The Permalink Manager Lite plugin for WordPress has a Stored Cross-Site Scripting vulnerability via post titles in the admin URI Editor interface in all versions up to, and including, 2.5.3.3. This vulnerability allows authenticated attackers with Contributor-level access and above to inject arbitrary web scripts in the admin Permalink Manager page, which will execute when an administrator accesses the Permalink Manager page. The vulnerability has a CVSS score of 6.4 and is classified as MEDIUM severity. WordPress users should update to a patched version to mitigate this risk.

Vendor
mbis
Product
Permalink Manager Lite
CVSS
MEDIUM 6.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-17
Original CVE updated
2026-06-17
Advisory published
2026-06-17
Advisory updated
2026-06-17

Who should care

WordPress administrators and users with Contributor-level access and above who use the Permalink Manager Lite plugin should be aware of this vulnerability and take steps to mitigate it. This vulnerability could allow attackers to inject malicious scripts, potentially leading to unauthorized actions or data breaches.

Technical summary

The Permalink Manager Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in the admin URI Editor interface. The vulnerability exists due to insufficient output escaping, allowing authenticated attackers with Contributor-level access and above to inject arbitrary web scripts. These scripts will execute when an administrator accesses the Permalink Manager page. The vulnerability is tracked as CVE-2026-8494 and has a CVSS score of 6.4.

Defensive priority

High

Recommended defensive actions

  • Update Permalink Manager Lite to a patched version (if available)
  • Limit Contributor-level access and above to only trusted users
  • Regularly monitor Permalink Manager pages for suspicious activity
  • Implement a Web Application Firewall (WAF) to detect and prevent XSS attacks
  • Keep WordPress and all plugins up-to-date with the latest security patches
  • Use a security plugin to scan for vulnerabilities and monitor site integrity

Evidence notes

The vulnerability was reported by [email protected] and is documented in the CVE-2026-8494 record on CVE.org and NVD. The vulnerability affects all versions of Permalink Manager Lite up to 2.5.3.3.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-8494 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-8494

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-8494 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-8494

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/permalink-manager/tags/2.5.3.1/includes/views/permalink-manager-uri-editor-post.php

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/permalink-manager/tags/2.5.3.3/includes/views/permalink-manager-uri-editor-post.php

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/permalink-manager/tags/2.5.3.4/includes/views/permalink-manager-uri-editor-post.php

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/permalink-manager/trunk/includes/views/permalink-manager-uri-editor-post.php

    [email protected]

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.