Junglewise Threat Intelligence

CVE-2026-57345: Webraketen Internal Links Manager unauthenticated XSS

CVE-2026-57345 · Severity: high · CVSS 7.1 · Published 2026-07-02

Executive brief

The Internal Links Manager plugin for WordPress, which automates SEO link building, contains a security flaw that allows attackers to inject malicious scripts into the website. If a site administrator or visitor interacts with a specially crafted link, the attacker could potentially hijack sessions, redirect users to malicious sites, or deface the website. This vulnerability can be exploited without needing a username or password.

Technical details

A Reflected Cross-Site Scripting (XSS) vulnerability exists in the Internal Links Manager plugin (versions 3.0.3 and below) for WordPress due to improper neutralization of user-supplied input during web page generation (CWE-79). An unauthenticated remote attacker can exploit this by tricking a user into clicking a malicious link or visiting a crafted page. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, which can lead to session hijacking or unauthorized actions. The issue is resolved in version 3.0.4.

Affected products

  • Webraketen Internal Links Manager <= 3.0.3

Timeline

  • 2026-05-08: other: Reported by researcher dodoh4t
  • 2026-06-29: advisory: Patchstack advisory published
  • 2026-07-02: disclosed: NVD publication date
  • 2026-07-02: patched: Version 3.0.4 released to address the vulnerability

References