Internal Links Manager
Internal Links Manager has 4 disclosed vulnerabilities in the WordSec catalog, reported between 2020 and 2026; all 4 are fixed as of September 2026. Their average CVSS score is 5.6, and the most serious one scores 7.2 out of 10. Severity breakdown: 0 critical and 1 high. 2025 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Scripting, behind 2 of the records (50%). Other recurring categories include Cross-Site Request Forgery (CSRF), Missing Authorization.
Every one of the 4 issues recorded for Internal Links Manager has a vendor fix available, so running the current release closes all known holes.
4 independent researchers contributed these findings, one record each. Internal Links Manager is installed on roughly 10,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2026-57345Internal Links Manager <= 3.0.3 - Unauthenticated Stored Cross-Site Scripting
Read the full analysisVulnerability Records

Internal Links Manager
Author
webraketen
Manual link building is a thing of the past! With our Internal Links Manager plugin, you can take your SEO performance to the next level. The plugin automatically optimizes your internal linking, strengthening your link juice and improving both your on-page SEO and the user experience of your website. Show Google your website structure – and guide your visitors specifically through your content at the same time. This way, you achieve better rankings and more visibility – without any technical effort. The most important features at a glance: Automated internal linking with precise fine-tuning (blacklist, keyword variants, HTML exclusions) Import & Export for efficient bulk processing Selective linking of individual words or phrases Statistics & Analytics – analyze click numbers and optimize your link strategy Start directly for free with the Basic version Our free Basic version already provides you with the perfect tool for automated linking – you don’t need any technical know-how. If you want even more control, the Pro version offers additional features such as WooCommerce & ACF support, Caching for maximum performance, and Prioritized email support.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C