Junglewise Threat Intelligence

CVE-2026-57353: Link Whisper Premium broken access control in WordPress plugin

CVE-2026-57353 · Severity: medium · CVSS 6.5 · Published 2026-07-02

Executive brief

Link Whisper Premium, a WordPress plugin used for internal link building and SEO optimization, contains a security flaw that allows low-privileged users to perform unauthorized actions. An attacker with a basic 'Subscriber' account could exploit this to modify site settings or data they should not have access to. This could lead to unauthorized changes to the website's SEO configuration or internal linking structure.

Technical details

A broken access control vulnerability exists in Link Whisper Premium versions up to and including 2.9.0 due to missing authorization checks (CWE-862). An authenticated attacker with Subscriber-level privileges can exploit this flaw via network requests to execute functions or modify data intended for higher-privileged users. The vulnerability specifically impacts integrity, as indicated by the CVSS vector. The issue is resolved in version 2.9.1, which introduces proper authorization validation.

Affected products

  • LinkWhisper Link Whisper Premium <= 2.9.0

Timeline

  • 2026-05-25: other: Reported by Austin Ginder
  • 2026-07-01: patched: Version 2.9.1 released
  • 2026-07-02: advisory

References