VYPR

SurfLink

by WordPress

CVEs (1)

  • CVE-2026-3552Jul 11, 2026
    risk 0.00cvss epss 0.00

    The SurfLink - Ultimate Link Manager plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the ajax_import_410() function in all versions up to 2.6.0. This is due to a missing capability check (current_user_can()) and missing…