CVE-2026-3552: CWE-862 Missing Authorization in surflabtech SurfLink – Link Manager & Backup Restore
The SurfLink - Ultimate Link Manager plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the ajax_import_410() function in all versions up to 2.6.0. This is due to a missing capability check (current_user_can()) and missing nonce verification (check_ajax_referer()) in the ajax_import_410() function, while all other AJAX handlers in the same class (ajax_add_single_410, ajax_save_editted_410, ajax_delete_410, ajax_bulk_410_delete, ajax_empty_410, ajax_export_410) properly implement both authorization and nonce checks. This makes it possible for authenticated attackers, with Subscriber-level access and above, to import arbitrary URLs into the 410 Gone database table via the surfl_import_410 AJAX action. Injected URLs will cause the site to return HTTP 410 Gone responses to all visitors accessing those paths, potentially causing denial of service for legitimate pages and SEO damage through search engine delisting.
AI Analysis
Technical Summary
CVE-2026-3552 is a missing authorization vulnerability (CWE-862) in the SurfLink – Link Manager & Backup Restore WordPress plugin. The ajax_import_410() AJAX handler function does not perform capability checks (current_user_can()) or nonce verification (check_ajax_referer()), unlike other AJAX handlers in the same class. This flaw allows any authenticated user with at least Subscriber privileges to inject arbitrary URLs into the 410 Gone database table via the surfl_import_410 AJAX action. Consequently, the site will respond with HTTP 410 Gone status for these URLs, which can disrupt legitimate site content availability and negatively impact SEO rankings. The vulnerability affects all versions up to 2.6.0. No official patch or remediation guidance is currently documented.
Potential Impact
An attacker with authenticated access at Subscriber level or higher can cause denial of service to legitimate site pages by injecting URLs that return HTTP 410 Gone responses. This can degrade user experience and cause SEO damage through search engine delisting of affected URLs. There is no direct confidentiality or availability impact beyond the denial of service effect on specific URLs.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict user roles that have access to the AJAX functionality or disable the plugin if possible. Monitor for plugin updates from the vendor addressing this missing authorization issue.
CVE-2026-3552: CWE-862 Missing Authorization in surflabtech SurfLink – Link Manager & Backup Restore
Description
The SurfLink - Ultimate Link Manager plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the ajax_import_410() function in all versions up to 2.6.0. This is due to a missing capability check (current_user_can()) and missing nonce verification (check_ajax_referer()) in the ajax_import_410() function, while all other AJAX handlers in the same class (ajax_add_single_410, ajax_save_editted_410, ajax_delete_410, ajax_bulk_410_delete, ajax_empty_410, ajax_export_410) properly implement both authorization and nonce checks. This makes it possible for authenticated attackers, with Subscriber-level access and above, to import arbitrary URLs into the 410 Gone database table via the surfl_import_410 AJAX action. Injected URLs will cause the site to return HTTP 410 Gone responses to all visitors accessing those paths, potentially causing denial of service for legitimate pages and SEO damage through search engine delisting.
CVSS v3.1
Score 4.3medium
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-3552 is a missing authorization vulnerability (CWE-862) in the SurfLink – Link Manager & Backup Restore WordPress plugin. The ajax_import_410() AJAX handler function does not perform capability checks (current_user_can()) or nonce verification (check_ajax_referer()), unlike other AJAX handlers in the same class. This flaw allows any authenticated user with at least Subscriber privileges to inject arbitrary URLs into the 410 Gone database table via the surfl_import_410 AJAX action. Consequently, the site will respond with HTTP 410 Gone status for these URLs, which can disrupt legitimate site content availability and negatively impact SEO rankings. The vulnerability affects all versions up to 2.6.0. No official patch or remediation guidance is currently documented.
Potential Impact
An attacker with authenticated access at Subscriber level or higher can cause denial of service to legitimate site pages by injecting URLs that return HTTP 410 Gone responses. This can degrade user experience and cause SEO damage through search engine delisting of affected URLs. There is no direct confidentiality or availability impact beyond the denial of service effect on specific URLs.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict user roles that have access to the AJAX functionality or disable the plugin if possible. Monitor for plugin updates from the vendor addressing this missing authorization issue.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Wordfence
- Date Reserved
- 2026-03-04T18:52:25.601Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a51c78468715ace4321e9fe
Added to database: 07/11/2026, 04:33:08 UTC
Last enriched: 07/18/2026, 15:28:00 UTC
Last updated: 08/24/2026, 22:52:10 UTC
Views: 48
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.