Pretty Url
Pretty Url has 3 disclosed vulnerabilities in the WordSec catalog, reported between 2023 and 2025; 2 are fixed and 1 remains unpatched as of September 2026. Their average CVSS score is 4.9, and the most serious one scores 6.1 out of 10. 2025 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Scripting, behind 2 of the records (67%). Other recurring categories include Cross-Site Request Forgery (CSRF).
2 of the records (67%) have a vendor fix, while 1 remain unpatched. The oldest unresolved one dates back to 2025.
2 independent researchers contributed these findings, most of them (2) reported by thiennv. Pretty Url is installed on roughly 80 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.
CVE-2025-22563Pretty Url <= 1.5.4 - Cross-Site Request Forgery
Read the full analysisVulnerability Records

Pretty Url
Author
faaiq
Description: Pretty URLs is a powerful WordPress plugin that lets you create clean, SEO-optimized custom URLs for any content type — including Posts, Pages, Categories, and Custom Post Types. Features: * Define custom SEO-friendly URLs for Posts, Pages, Categories, and Custom Post Types * Add custom Meta Titles, Meta Descriptions, and Meta Keywords * Control search engine behavior with NOFOLLOW and NOINDEX tags * Enable or disable meta tags individually for full flexibility * Supports archive pages, single posts, and taxonomy terms Boost your site’s search engine visibility and gain complete control over how your content appears in search results — without needing to touch your theme or core files. Installation: 1. Upload the prettyurl plugin folder to your /wp-content/plugins/ directory 2. Activate the plugin via the Plugins menu in your WordPress admin 3. Navigate to “Pretty URLs” in the admin menu to create and manage custom URLs for categories and post type archive pages 4. For single posts, pages, and custom post types, a “Pretty URL” meta box will be available on the edit screen 5. For support or customizations, contact: [scriptut.com] contact page Arbitrary section 1
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C