WP Better Permalinks
WP Better Permalinks has one disclosed vulnerability in the WordSec catalog, all reported in 2019; it is fixed as of September 2026. Their average CVSS score is 8.8, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 1 high.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).
The one issue recorded for WP Better Permalinks has a vendor fix available, so running the current release closes it.
WP Better Permalinks is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2019-15835WP Better Permalinks < 3.0.5 - Cross-Site Request Forgery
Read the full analysisVulnerability Records

WP Better Permalinks
Author
Mateusz Gbiorczyk
Set custom friendly permalinks structure: Custom Post Type > Taxonomy > Post and Custom Post Type > Taxonomy instead of default WordPress structure. Default permalinks structure in WordPress: Custom Post Type > Post Taxonomy > Single Term Friendly permalinks structure pattern available using this plugin: Custom Post Type > Single Term (or Term tree) > Post Custom Post Type > Post (when no term is selected) Custom Post Type > Single Term (or Term tree) The plugin allows you to set your own structure with a few clicks. Everything works automatically, no need to add any additional code. Please also read the FAQ below. Thank you for being with us!
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C