CVE-2025-23989
WordPress Internal Link Builder plugin <= 1.0 - CSRF to Stored XSS vulnerability
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Cross-Site Request Forgery (CSRF) vulnerability in Alessandro Piconi Internal Link Builder internal-link-builder allows Cross Site Request Forgery.This issue affects Internal Link Builder: from n/a through <= 1.0.
| CWE | CWE-352 |
| Vendor | alessandro piconi |
| Product | internal link builder |
| Published | Jan 31, 2025 |
| Last Updated | Apr 1, 2026 |
Stay Ahead of the Next One
Get instant alerts for alessandro piconi internal link builder
Be the first to know when new unknown vulnerabilities affecting alessandro piconi internal link builder are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Alessandro Piconi / Internal Link Builder
0 โค 1.0
References
Credits
SOPROBRO | Patchstack Bug Bounty Program