WordPress Internal Link Optimiser Missing Authorization Vulnerability Allowing Settings Change

Vulnerability

A missing authorization vulnerability has been identified in the WordPress Internal Link Optimiser plugin, specifically in versions through 5.1.2. This vulnerability allows for exploitation of improperly configured access control security levels, potentially leading to unauthorized changes in plugin settings.

Impact

Exploitation of this vulnerability could result in unauthorized changes to the plugin's settings, allowing attackers to manipulate internal link optimization features without proper authorization.

Remediation

Users of the WordPress Internal Link Optimiser plugin should update to version 5.1.3 or later to address this vulnerability. Patchstack users can enable auto-update for vulnerable plugins.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
7.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.