Impact
The flaw is a missing authorization check in the Internal Linking of Related Contents plugin, allowing a user with an incorrectly configured role to access or manipulate internal linking functionalities that should be restricted. This can lead to unauthorized editing or creation of linked content, potentially compromising the integrity and consistency of the site’s internal structure. The weakness is identified as CWE-862, a broken access control vulnerability.
Affected Systems
WordPress installations running the alexvtn Internal Linking of Related Contents plugin version 1.1.8 or earlier are impacted. No additional vendor or product details are available beyond the plugin name and the affected version threshold.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and the EPSS score of less than 1% suggests a low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is an authenticated WordPress user whose role or capabilities have been incorrectly configured to bypass the access control check. The vulnerability can be exploited by providing the user with capabilities to modify internal links, which may lead to content manipulation or site instability.
OpenCVE Enrichment
EUVD