Description
Cross-Site Request Forgery (CSRF) vulnerability in Alessandro Piconi Internal Link Builder internal-link-builder allows Cross Site Request Forgery.This issue affects Internal Link Builder: from n/a through <= 1.0.
Published: 2025-01-31
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A Cross‑Site Request Forgery flaw exists in the Internal Link Builder plugin for WordPress that permits an attacker to perform unauthorized actions on behalf of any authenticated user. The vulnerability is capable of injecting malicious JavaScript that persists within the site—which can be executed whenever a user visits the affected page—thereby giving an attacker the ability to steal credentials, deface content, or perform further attacks on the site. Although the description focuses on CSRF, the indicated stored XSS outcome suggests that payload execution can be achieved through the plugin’s data handling functions.

Affected Systems

The issue affects the Alessandro Piconi Internal Link Builder plugin for WordPress, specifically versions n/a through 1.0. If a site is running one of these releases, the vulnerability is present and exploitable unless mitigated. No other vendors or product families are listed as impacted.

Risk and Exploitability

The CVSS score of 7.1 reflects a moderate‑to‑severe threat, while the EPSS value of less than 1 % indicates that exploitation is currently considered unlikely but not impossible. The vulnerability is not identified in the CISA KEV catalog, suggesting it has not been observed in widespread attacks. The likely attack vector is web‑based, requiring a victim to be logged in as a user with permissions to utilize the plugin’s administrative functions. If an attacker can persuade a legitimate user to perform a specific action, the CSRF mechanism could submit malicious data that is stored and later executed as part of the site’s content.

Generated by OpenCVE AI on May 1, 2026 at 17:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Internal Link Builder plugin to the latest available version (post‑1.0), which removes the CSRF vector
  • If an upgrade cannot be performed immediately, disable the plugin on all non‑admin sites or enforce strict role‑based access control to prevent general users from activating its features
  • Employ a site‑wide CSRF token mechanism or security plugin that validates state‑changing requests to add an additional defense layer

Generated by OpenCVE AI on May 1, 2026 at 17:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3585 Cross-Site Request Forgery (CSRF) vulnerability in Alessandro Piconi - SabLab Internal Link Builder allows Cross Site Request Forgery. This issue affects Internal Link Builder: from n/a through 1.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Alessandro Piconi - SabLab Internal Link Builder allows Cross Site Request Forgery. This issue affects Internal Link Builder: from n/a through 1.0. Cross-Site Request Forgery (CSRF) vulnerability in Alessandro Piconi Internal Link Builder internal-link-builder allows Cross Site Request Forgery.This issue affects Internal Link Builder: from n/a through <= 1.0.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Fri, 11 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00019}

epss

{'score': 0.00023}


Mon, 10 Feb 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 31 Jan 2025 08:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Alessandro Piconi - SabLab Internal Link Builder allows Cross Site Request Forgery. This issue affects Internal Link Builder: from n/a through 1.0.
Title WordPress Internal Link Builder plugin <= 1.0 - CSRF to Stored XSS vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-11T23:25:31.869Z

Reserved: 2025-01-16T11:33:22.828Z

Link: CVE-2025-23989

cve-icon Vulnrichment

Updated: 2025-01-31T15:36:38.668Z

cve-icon NVD

Status : Deferred

Published: 2025-01-31T09:15:09.427

Modified: 2026-06-17T08:57:50.827

Link: CVE-2025-23989

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T18:00:09Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)