PT-2026-57396 · WordPress · Surflink - Ultimate Link Manager

·

CVE-2026-3552

·

Published

2026-07-11

·

Updated

2026-07-12

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions SurfLink - Ultimate Link Manager versions prior to 2.6.1
Description Unauthorized data modification is possible due to a missing capability check and missing nonce verification in the ajax import 410() function. While other AJAX handlers in the same class implement proper authorization and nonce checks, this specific function allows authenticated attackers with Subscriber-level access and above to import arbitrary URLs into the 410 Gone database table via the surfl import 410 AJAX action. This can lead to the site returning HTTP 410 Gone responses to visitors accessing those paths, potentially resulting in a denial of service for legitimate pages and SEO damage through search engine delisting.
Recommendations Update to version 2.6.1 or later. As a temporary workaround, restrict access to the ajax import 410() function to prevent unauthorized imports.

Fix

DoS

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-3552

Affected Products

Surflink - Ultimate Link Manager