🔐 CVE Alert

CVE-2025-11734

MEDIUM 5.4

Broken Link Checker by AIOSEO – Easily Fix/Monitor Internal and External links <= 1.2.5 - Missing Authorization to Authenticated (Contributor+) Arbitrary Post Trashing

CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th

The Broken Link Checker by AIOSEO – Easily Fix/Monitor Internal and External links plugin for WordPress is vulnerable to unauthorized post modification due to missing authorization in all versions up to, and including, 1.2.5. This is due to the plugin registering a REST API endpoint that only checks for a broad capability (aioseo_blc_broken_links_page) that is granted to contributor level users, without verifying the user's permission to perform actions on the specific post being targeted. This makes it possible for authenticated attackers, with contributor level access and above, to trash arbitrary posts via the DELETE /wp-json/aioseoBrokenLinkChecker/v1/post endpoint.

CWE CWE-862
Vendor aioseo
Product broken link checker by aioseo – easily fix/monitor internal and external links
Published Nov 18, 2025
Last Updated Apr 8, 2026
Stay Ahead of the Next One

Get instant alerts for aioseo broken link checker by aioseo – easily fix/monitor internal and external links

Be the first to know when new medium vulnerabilities affecting aioseo broken link checker by aioseo – easily fix/monitor internal and external links are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

aioseo / Broken Link Checker by AIOSEO – Easily Fix/Monitor Internal and External links
0 ≤ 1.2.5

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/0254cd1b-f8f6-400e-a48e-81bd553fe8d1?source=cve plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset/3390304/broken-link-checker-seo

Credits

Lucas Montes