CVE-2025-23989
WordPress Internal Link Builder plugin <= 1.0 - CSRF to Stored XSS vulnerability
CVSS Score
7.1
EPSS Score
0.1%
EPSS Percentile
30th
Cross-Site Request Forgery (CSRF) vulnerability in Alessandro Piconi Internal Link Builder internal-link-builder allows Cross Site Request Forgery.This issue affects Internal Link Builder: from n/a through <= 1.0.
| CWE | CWE-352 |
| Vendor | alessandro piconi |
| Product | internal link builder |
| Published | Jan 31, 2025 |
| Last Updated | May 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for alessandro piconi internal link builder
Be the first to know when new high vulnerabilities affecting alessandro piconi internal link builder are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
Low
Affected Versions
Alessandro Piconi / Internal Link Builder
0 โค 1.0
References
Credits
SOPROBRO | Patchstack Bug Bounty Program