WordPress · Permalink Manager Lite · CVE-2026-8494
**Name of the Vulnerable Software and Affected Versions**
Permalink Manager Lite versions prior to 2.5.3.4
**Description**
The Permalink Manager Lite plugin for WordPress contains a Stored Cross-Site Scripting issue in the admin URI Editor interface caused by insufficient output escaping. Authenticated attackers with Contributor-level access or higher can inject arbitrary web scripts through post titles. These scripts execute when an administrator accesses the admin Permalink Manager page.
**Recommendations**
Update to a version later than 2.5.3.3.