Description
Unauthenticated Cross Site Scripting (XSS) in Internal Links Manager <= 3.0.3 versions.
Published: 2026-07-02
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Unauthenticated Cross Site XSS in the Webraketen Internal Links Manager plugin for WordPress versions 3.0.3 or earlier allows attackers to insert arbitrary script code that the plugin will process and display in users’ browsers when a page containing the plugin is rendered. Based on the description, it is inferred that this could enable the attacker to modify page content or perform other malicious actions. Authentication is not required to exploit this flaw.

Affected Systems

WordPress sites that are running the Webraketen Internal Links Manager plugin version 3.0.3 or older are affected. The fix is included in version 3.0.4 and later.

Risk and Exploitability

The CVSS score of 7.1 classifies the vulnerability as high. The EPSS score of less than 1% indicates a very low but non‑zero probability of exploitation. It is not listed in the CISA KEV catalog. The description indicates that the attack vector is unauthenticated, allowing an attacker to exploit the vulnerable plugin and subsequently execute code in users’ browsers without needing credentials.

Generated by OpenCVE AI on July 21, 2026 at 11:57 UTC.

Remediation

Vendor Solution

Update the WordPress Internal Links Manager Plugin to the latest available version (at least 3.0.4).


OpenCVE Recommended Actions

  • Upgrade the Internal Links Manager plugin to version 3.0.4 or later.
  • Temporarily disable or deactivate the plugin on or remove it entirely until the patch can be applied.
  • Deploy a strict Content Security Policy that disallows inline scripts and restricts script sources to trusted hosts.

Generated by OpenCVE AI on July 21, 2026 at 11:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 02 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in Internal Links Manager <= 3.0.3 versions.
Title WordPress Internal Links Manager plugin <= 3.0.3 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-02T12:14:00.631Z

Reserved: 2026-06-24T12:45:24.971Z

Link: CVE-2026-57345

cve-icon Vulnrichment

Updated: 2026-07-02T12:13:57.383Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T12:00:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')