Description
Missing Authorization vulnerability in webraketen Internal Links Manager seo-automated-link-building allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Internal Links Manager: from n/a through <= 2.5.2.
Published: 2025-01-24
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Missing Authorization in webraketen Internal Links Manager allows an attacker to override incorrectly configured access control settings, enabling unauthorized use of the plugin’s internal link management functions. This broken access control can expose hidden content, manipulate site navigation, or modify link data, potentially harming site integrity and trust. The primary weakness is identified as CWE‑862, indicating that user permissions are not properly enforced by the plugin.

Affected Systems

The vulnerability affects the webraketen Internal Links Manager WordPress plugin for all versions up to and including 2.5.2. Any WordPress site that has installed this plugin within that version range is potentially affected. No specific distribution or platform details beyond WordPress are listed.

Risk and Exploitability

The CVSS score of 4.3 places the issue at a medium severity level, while the EPSS score of less than 1% suggests a very low likelihood of widespread exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector involves a user who has any authenticated access to the WordPress site, who can then exploit the lack of authorization checks. The exact impact for a given site depends on the roles and capabilities assigned to users, but the potential for unauthorized access to plugin features remains.

Generated by OpenCVE AI on May 1, 2026 at 18:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Internal Links Manager plugin to the latest version (or at least 2.5.3) to obtain the vendor’s fix for the broken access control issue.
  • If an update is not immediately available, consider disabling the plugin or restricting its capabilities to administrative users only until a patch is applied.
  • Re‑evaluate and tighten WordPress user role permissions to ensure that only trusted administrators have access to the plugin’s features, mitigating the risk of unauthorized exploitation.

Generated by OpenCVE AI on May 1, 2026 at 18:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3873 Missing Authorization vulnerability in webraketen Internal Links Manager allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Internal Links Manager: from n/a through 2.5.2.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in webraketen Internal Links Manager allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Internal Links Manager: from n/a through 2.5.2. Missing Authorization vulnerability in webraketen Internal Links Manager seo-automated-link-building allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Internal Links Manager: from n/a through <= 2.5.2.
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Fri, 24 Jan 2025 17:30:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in webraketen Internal Links Manager allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Internal Links Manager: from n/a through 2.5.2.
Title WordPress Internal Links Manager plugin <= 2.5.2 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:31.725Z

Reserved: 2025-01-23T14:52:05.567Z

Link: CVE-2025-24679

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2025-01-24T18:15:41.630

Modified: 2026-06-17T08:59:25.657

Link: CVE-2025-24679

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T18:45:15Z

Weaknesses