PT-2026-57396 · WordPress · Surflink - Ultimate Link Manager
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
SurfLink - Ultimate Link Manager versions prior to 2.6.1
Description
Unauthorized data modification is possible due to a missing capability check and missing nonce verification in the
ajax import 410() function. While other AJAX handlers in the same class implement proper authorization and nonce checks, this specific function allows authenticated attackers with Subscriber-level access and above to import arbitrary URLs into the 410 Gone database table via the surfl import 410 AJAX action. This can lead to the site returning HTTP 410 Gone responses to visitors accessing those paths, potentially resulting in a denial of service for legitimate pages and SEO damage through search engine delisting.Recommendations
Update to version 2.6.1 or later.
As a temporary workaround, restrict access to the
ajax import 410() function to prevent unauthorized imports.Fix
DoS
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Surflink - Ultimate Link Manager