Description
Missing Authorization vulnerability in Md Yeasin Ul Haider URL Shortener exact-links allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects URL Shortener: from n/a through <= 3.0.7.
Published: 2025-07-16
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A missing authorization check in the WordPress URL Shortener plugin allows any user interacting with the site to invoke restricted actions that should be limited to privileged users. This broken access control flaw could enable an attacker to create, modify, or delete shortened URLs and potentially gain further influence over the site’s content or structure. The weakness is a classic example of CWE‑862, where authorization checks fail to constrain user privileges, leading to integrity and availability impacts on the application.

Affected Systems

The defect exists in the Md Yeasin Ul Haider URL Shortener plugin (exact-links) for WordPress versions 3.0.7 and earlier. Any WordPress installation that has this plugin installed and has not migrated to a later version is potentially vulnerable.

Risk and Exploitability

The CVSS score of 8.6 indicates a high severity due to the breadth of potential impact and the simplicity of the exploit. The EPSS score of less than 1% suggests that the probability of exploitation in the wild is low at this time, and the vulnerability is not yet reported in the CISA KEV catalog. Nevertheless, because the flaw permits unauthenticated or minimally privileged users to trigger protected plugin functionality, an active attacker could exploit it by sending crafted HTTP requests to the plugin’s endpoints. The vulnerability does not require prerequisite code execution, so it can be leveraged directly against a live site where the plugin is exposed.

Generated by OpenCVE AI on May 2, 2026 at 01:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the WordPress URL Shortener plugin to a version that addresses this authorization issue (e.g., any release newer than 3.0.7).
  • If an update is unavailable, remove or disable the plugin entirely to eliminate the attack surface.
  • Configure your web application firewall or site‑wide permissions to restrict access to the plugin’s URLs to users with administrator privileges, thereby compensating for the missing authorization check.

Generated by OpenCVE AI on May 2, 2026 at 01:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-21603 Missing Authorization vulnerability in Md Yeasin Ul Haider URL Shortener allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects URL Shortener: from n/a through 3.0.7.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Md Yeasin Ul Haider URL Shortener allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects URL Shortener: from n/a through 3.0.7. Missing Authorization vulnerability in Md Yeasin Ul Haider URL Shortener exact-links allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects URL Shortener: from n/a through <= 3.0.7.
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L'}


Wed, 16 Jul 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00037}


Wed, 16 Jul 2025 11:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Md Yeasin Ul Haider URL Shortener allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects URL Shortener: from n/a through 3.0.7.
Title WordPress URL Shortener <= 3.0.7 - Broken Access Control Vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:52.063Z

Reserved: 2025-03-11T08:10:27.473Z

Link: CVE-2025-28965

cve-icon Vulnrichment

Updated: 2025-07-16T13:32:48.315Z

cve-icon NVD

Status : Deferred

Published: 2025-07-16T12:15:24.233

Modified: 2026-06-17T09:04:58.053

Link: CVE-2025-28965

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T01:15:06Z

Weaknesses