CVE-2026-66464: WordPress Internal Link Optimiser plugin <= 5.2.7 - Broken Access Control vulnerability
Published Aug 13, 2026
·Updated
Unauthenticated Broken Access Control in Internal Link Optimiser <= 5.2.7 versions.
Affected Software
1 affected component
wordpress.org/internal-link-optimiser<=5.2.7
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/Internal Link Optimiserto a version that resolves this vulnerability.Fixed in 5.2.7
Event History
Aug 13, 2026
CVE Published
via MITRE·01:37 PM
Data Sourced
via MITRE·01:37 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-66464?
The severity of CVE-2026-66464 is classified as medium with a score of 6.5.
2
What is the key issue in CVE-2026-66464?
CVE-2026-66464 involves an unauthenticated broken access control vulnerability in the Internal Link Optimiser plugin for WordPress.
3
How do I fix CVE-2026-66464?
To fix CVE-2026-66464, update the Internal Link Optimiser plugin to version 5.2.8 or later.
4
Which versions of the Internal Link Optimiser plugin are affected by CVE-2026-66464?
CVE-2026-66464 affects Internal Link Optimiser plugin versions up to and including 5.2.7.
5
Is authentication required to exploit CVE-2026-66464?
No, CVE-2026-66464 can be exploited without any authentication.