Impact
Unauthenticated Cross Site XSS in the Webraketen Internal Links Manager plugin for WordPress versions 3.0.3 or earlier allows attackers to insert arbitrary script code that the plugin will process and display in users’ browsers when a page containing the plugin is rendered. Based on the description, it is inferred that this could enable the attacker to modify page content or perform other malicious actions. Authentication is not required to exploit this flaw.
Affected Systems
WordPress sites that are running the Webraketen Internal Links Manager plugin version 3.0.3 or older are affected. The fix is included in version 3.0.4 and later.
Risk and Exploitability
The CVSS score of 7.1 classifies the vulnerability as high. The EPSS score of less than 1% indicates a very low but non‑zero probability of exploitation. It is not listed in the CISA KEV catalog. The description indicates that the attack vector is unauthenticated, allowing an attacker to exploit the vulnerable plugin and subsequently execute code in users’ browsers without needing credentials.
OpenCVE Enrichment