VYPR
High severity7.6NVD Advisory· Published Dec 16, 2025· Updated Apr 27, 2026

CVE-2025-67962

CVE-2025-67962

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AIOSEO Plugin Team Broken Link Checker broken-link-checker-seo allows SQL Injection.This issue affects Broken Link Checker: from n/a through <= 1.2.6.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

SQL injection in Broken Link Checker plugin (≤1.2.6) allows unauthenticated attackers to extract or modify the WordPress database.

Vulnerability

Overview The Broken Link Checker plugin for WordPress (versions up to and including 1.2.6) contains an SQL injection vulnerability due to improper neutralization of special elements used in an SQL command [1]. This flaw allows an attacker to inject arbitrary SQL queries into the database layer.

Exploitation

No authentication is required to exploit this vulnerability, making it accessible to any remote attacker. Attackers can target thousands of websites running the vulnerable plugin in mass-exploit campaigns [1]. The attack vector is network-based and requires no user interaction.

Impact

Successful exploitation could allow an attacker to directly interact with the database, including stealing sensitive information, modifying data, or potentially gaining further access to the WordPress site [1]. The CVSS v3 score is 7.6 (High), reflecting the serious risk to confidentiality, integrity, and availability.

Mitigation

The vulnerability has been patched version 1.2.7 resolves the issue [1]. Users are strongly advised to update immediately update immediately. If updating is not possible, consult a hosting provider or web developer for assistance. Auto-update features can be enabled for vulnerable plugins.

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.