plugin

Rb Internal Links Vulnerabilities

2 known security issues reported for the Rb Internal Links WordPress plugin. Most recent disclosed Jun 13, 2022.

1 critical

Running Rb Internal Links on your site? Check whether your installed version is affected.

Scan your site free

RB Internal Links [rb-internal-links] <= 2.0.16 (unfixed + closed)

unknown

[en] The RB Internal Links WordPress plugin through 2.0.16 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack, as well as perform Stored Cross-Site Scripting attacks due to the lack of sanitisation and escaping

Affected:
up to 2.0.16
Fix:
No patched version reported
Disclosed:
Jun 13, 2022

CVE-2022-1759 on NVD →

RB Internal Links <= 2.0.16 - Cross-Site Request Forgery to Settings update and Cross-Site Scripting

critical

The RB Internal Links WordPress plugin through 2.0.16 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack, as well as perform Stored Cross-Site Scripting attacks due to the lack of sanitisation and escaping

CVSS:
9.6
Affected:
up to 2.0.16
Fix:
No patched version reported
Disclosed:
May 23, 2022

CVE-2022-1759 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database