Impact
The Internal Link Optimiser plugin contains a flaw that allows a malicious user to send a forged request that bypasses the plugin’s CSRF protection, resulting in arbitrary JavaScript code being stored in the site’s content. This stored XSS is an instance of CWE‑352 and, based on standard XSS behavior, could be executed in any visitor’s browser that views the compromised content.
Affected Systems
WordPress sites running Toast Plugins Internal Link Optimiser plugin versions through 5.1.3 are vulnerable; the CVE data does not specify a lower bound for the earliest affected release, indicating it may be any version up to 5.1.3.
Risk and Exploitability
The CVSS score of 7.1 indicates high potential impact, while the EPSS score of < 1 % suggests low current exploitation likelihood. The vulnerability involves a CSRF flaw that permits the attacker to send a forged request to the plugin, leading to a stored XSS that, based on standard XSS behavior, could affect all site visitors who view the compromised content. The CVE notes that the issue is not listed in the CISA KEV catalog, but it remains a serious concern for sites that still run the affected plugin version.
OpenCVE Enrichment
EUVD