What is CVE-2026-5062?
A critical SQL injection vulnerability has been discovered in the PrettyLinks plugin for WordPress, affecting versions up to 3.6.20. Attackers could exploit the 's' parameter to compromise the database. Immediate plugin update or temporary deactivation is strongly recommended.
Azərbaycanca: WordPress üçün PrettyLinks plaginində kritik SQL injection zəifliyi aşkarlanıb. Bu, 's' parametri vasitəsilə hücumçulara verilənlər bazasına müdaxilə etməyə imkan verə bilər. Veb sayt inzibatçıları dərhal plagini ən son versiyaya yeniləməli və ya müvəqqəti olaraq deaktiv etməlidir.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which versions of the PrettyLinks plugin are affected by CVE-2026-5062?
Versions up to 3.6.20 are affected.
What is the recommended mitigation for CVE-2026-5062?
Administrators should immediately update the plugin to the latest version or temporarily deactivate it.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.