Description
Missing Authorization vulnerability in Toast Plugins Internal Link Optimiser internal-link-finder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Internal Link Optimiser: from n/a through <= 5.1.2.
Published: 2025-04-10
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Toast Plugins Internal Link Optimiser WordPress plugin suffers from a missing authorization check that allows users to alter settings without the required privileges. This flaw, classified as CWE-862, enables an attacker who can reach the plugin’s settings page to modify configuration values, potentially opening avenues for further compromise such as enabling features that facilitate other attacks or exposing sensitive data.

Affected Systems

Any WordPress site running the Toast Plugins Internal Link Optimiser plugin version 5.1.2 or earlier is affected. The vulnerability applies to all installations that have not yet upgraded beyond version 5.1.2, regardless of the specific WordPress theme or server environment.

Risk and Exploitability

The CVSS score of 6.5 places the flaw in the medium severity range, while the EPSS score of less than 1% indicates a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The attack vector is likely remote, targeting WordPress administrators or anyone who gains access to the site’s administrative interface. Based on the description, it is inferred that the attacker must gain access to the plugin’s settings page through the administrative interface. If the plugin’s settings page is accessible without proper authentication, the conditions for exploitation are simplified, but the attacker still requires some level of access to the WordPress installation, which typically limits the risk to sites with exposed admin interfaces or weak credentials.

Generated by OpenCVE AI on May 1, 2026 at 10:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Internal Link Optimiser to the latest version that contains the fix for missing authorization checks.
  • If an immediate update is not possible, restrict access to the plugin’s settings page by disabling the settings functionality for all roles except administrators.
  • Review and tighten WordPress user roles, ensuring that only trusted accounts have permission to manage plugins and settings.
  • Enable two‑factor authentication for all administrative accounts to reduce the risk of credential compromise.
  • Maintain regular, secure backups of the site so that any changes made by an attacker can be reversed.

Generated by OpenCVE AI on May 1, 2026 at 10:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-10455 Missing Authorization vulnerability in Toast Plugins Internal Link Optimiser allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Internal Link Optimiser: from n/a through 5.1.2.
History

Fri, 24 Apr 2026 11:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Toast Plugins Internal Link Optimiser allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Internal Link Optimiser: from n/a through 5.1.2. Missing Authorization vulnerability in Toast Plugins Internal Link Optimiser internal-link-finder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Internal Link Optimiser: from n/a through <= 5.1.2.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}


Thu, 10 Apr 2025 08:15:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Toast Plugins Internal Link Optimiser allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Internal Link Optimiser: from n/a through 5.1.2.
Title WordPress Internal Link Optimiser plugin <= 5.1.2 - Settings Change vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:19.628Z

Reserved: 2025-04-04T10:02:07.011Z

Link: CVE-2025-32243

cve-icon Vulnrichment

Updated: 2025-04-10T15:52:22.373Z

cve-icon NVD

Status : Deferred

Published: 2025-04-10T08:15:20.237

Modified: 2026-04-23T15:28:49.373

Link: CVE-2025-32243

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T10:45:05Z

Weaknesses