Unauthenticated Broken Access Control in Internal Link Optimiser by WordPress
CVE-2026-66464

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
13 August 2026

What is CVE-2026-66464?

The vulnerability presents an unauthenticated broken access control issue in versions of the Internal Link Optimiser plugin for WordPress. This flaw can potentially allow unauthorized users to access and manipulate sensitive data, posing significant risks to site integrity. It is crucial for WordPress users to patch their installations to safeguard against potential exploitation.

Affected Version(s)

Internal Link Optimiser <= 5.2.7

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Legion Hunter | Patchstack Bug Bounty Program
.