Impact
Unauthenticated broken access control exists in WordPress Internal Link Optimiser plugin versions 5.2.7 and earlier, allowing attackers to invoke administrative functions that are normally protected. The weakness is classified as CWE-862, indicating a failure to enforce proper user authorization checks. This flaw could enable an attacker to modify site link data, inject malicious content, or otherwise tamper with site functionality without requiring valid credentials.
Affected Systems
The vulnerability targets the Toast Plugins Internal Link Optimiser plugin for WordPress, affecting all installations of version 5.2.7 and prior. Administrators should verify the exact plugin version and assess whether it is running within a production environment.
Risk and Exploitability
With a CVSS score of 6.5, this issue presents moderate severity. The EPSS score is not available, but the vulnerability is not listed in the CISA KEV catalog. Because the flaw permits unauthenticated access, the attack vector is likely via standard HTTP requests to the plugin’s administrative endpoints, requiring no special privileges or environment setup. Once access is gained, an attacker can freely manipulate link optimisations and potentially compromise site integrity.
OpenCVE Enrichment