PT-2026-81124 · WordPress · Betterlinks+1

·

CVE-2026-19801

·

Published

2026-08-25

·

Updated

2026-08-25

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions BetterLinks versions prior to 3.1.1
Description An authorization bypass exists because the plugin fails to properly verify if a user is authorized to perform specific actions. Authenticated attackers with subscriber-level access or higher can create arbitrary short URLs with controlled slugs and redirect destinations, which can be used for phishing and SEO abuse. This issue requires the Fluent Boards companion plugin to be installed and active to ensure the FLUENT BOARDS constant is defined. The exploitation is further enabled by the betterlinks admin nonce nonce being exposed on every frontend page via wp localize script, making it available to any authenticated user.
Recommendations Update BetterLinks to a version newer than 3.1.0.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19801

Affected Products

Betterlinks
Fluentboards