← WordPress Vulnerabilities
WordPress security by component

Internal Link Builder

Internal Link Builder is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Jan 14, 2026; the highest CVE/CNA score is 7.1.

Plugin slug: internal-link-builder

CVE-2025-14725: Internal Link Builder: Cross-site scripting

Internal Link Builder is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.

PublishedJan 14, 2026
Safe version guidanceSee mitigation notes
Safe version
Jan 14, 2026 CVE-2025-14725
Internal Link Builder: Cross-site scripting
Internal Link Builder is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.4
NVDPending
Jan 31, 2025 CVE-2025-23989
Internal Link Builder: Cross-site request forgery
Internal Link Builder is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE7.1
NVDPending