CVE-2024-11009

Published
View on NVD ↗
CVSS v3
4.9
MEDIUM
CVSS v2
N/A
Affected
1
PROJECT

Description

The Internal Linking for SEO traffic & Ranking – Auto internal links (100% automatic) plugin for WordPress is vulnerable to time-based SQL Injection via the ‘post_id’ parameter in all versions up to, and including, 1.2.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

<p><strong>Automatic Internal Links for SEO</strong> is a WordPress plugin that creates internal links from focus keywords and optional custom link rules.</p> <p>It is designed for site owners who want to improve internal linking coverage without manually adding links to every page.</p> <p>Official documentation: <a href="https://autolinksforseo.com/internal-links" rel="nofollow ugc">https://autolinksforseo.com/internal-links</a></p> <h4>Quick product facts</h4> <ul> <li><strong>Product type:</strong> WordPress internal linking plugin</li> <li><strong>Core signal:</strong> focus keywords</li> <li><strong>Supported SEO plugins:</strong> Yoast SEO, Rank Math, All in One SEO (AIOSEO)</li> <li><strong>Free workflow:</strong> manual SYNC</li> <li><strong>Pro workflow:</strong> continuous auto-sync / background sync</li> <li><strong>Manual custom links:</strong> yes</li> <li><strong>External links:</strong> yes</li> <li><strong>WooCommerce product pages:</strong> Pro</li> <li><strong>External AI API:</strong> no</li> <li><strong>Goal:</strong> improve internal linking structure and reduce manual work</li> </ul> <h4>What Automatic Internal Links does</h4> <p>Automatic Internal Links scans focus keywords and creates link rules that are then applied to supported post content.</p> <p>Depending on your configuration, the plugin can:</p> <ul> <li>create internal links from focus keywords</li> <li>create custom manual internal links</li> <li>create custom external links</li> <li>limit the number of links per page</li> <li>use partial match or exact-style matching</li> <li>add bold formatting to linked anchor text</li> <li>add <code>nofollow</code> and <code>target="_blank"</code> where needed</li> <li>exclude HTML tags, excluded keywords, URLs, or specific pages</li> <li>keep an activity log of synchronized links</li> </ul> <h4>What Automatic Internal Links does not do</h4> <p>Automatic Internal Links does <strong>not</strong> do the following:</p> <ul> <li>it does <strong>not</strong> guarantee rankings</li> <li>it does <strong>not</strong> replace editorial judgment for anchor text strategy</li> <li>it does <strong>not</strong> support ACF content fields</li> <li>it does <strong>not</strong> fully distinguish identical words across languages on multilingual sites</li> <li>it does <strong>not</strong> add taxonomy or product category linking out of the box</li> <li>it does <strong>not</strong> require an external AI or SaaS API</li> </ul> <p>This distinction matters: the plugin is a <strong>focus-keyword-driven linking engine</strong>, not a promise of automatic SEO success.</p> <h4>Free vs Pro</h4> <p>This distinction must be clear.</p> <p><strong>Free edition</strong><br /> &#8211; manual <strong>SYNC</strong> workflow<br /> &#8211; settings and exclusions<br /> &#8211; custom internal links<br /> &#8211; custom external links<br /> &#8211; activity log<br /> &#8211; supported SEO plugins and selected post types<br /> &#8211; suitable for controlled, manual synchronization</p> <p><strong>Pro edition</strong><br /> &#8211; <strong>AUTO LINKS</strong> / continuous auto-sync<br /> &#8211; background sync with schedule and batch controls<br /> &#8211; WooCommerce product page support<br /> &#8211; product pages for custom internal and external links<br /> &#8211; per-page disable control</p> <p>If you want the plugin to keep new or updated content synchronized automatically, that is a <strong>Pro</strong> feature.</p> <p>See plans and documentation: <a href="https://autolinksforseo.com/pricing" rel="nofollow ugc">https://autolinksforseo.com/pricing</a></p> <h4>How it works</h4> <ol> <li>Select the post types you want to cover</li> <li>Configure exclusions and linking rules</li> <li>The plugin reads focus keywords from the supported SEO plugin</li> <li>Run <strong>SYNC</strong> to build links from those focus keywords</li> <li>Review the activity log</li> <li>Optionally add custom internal or external links</li> <li>In Pro, enable continuous auto-sync for new and updated content</li> </ol> <h4>Why this plugin is useful</h4> <p>Internal linking often fails for the same reasons:</p> <ul> <li>content grows faster than editors can maintain links</li> <li>deep pages stay underlinked</li> <li>orphaned or weak pages remain invisible in the internal graph</li> <li>anchor text is inconsistent across the site</li> </ul> <p>Automatic Internal Links helps you apply a repeatable internal linking workflow instead of depending on manual link placement everywhere.</p> <p>It also works naturally as part of a broader SEO pipeline:</p> <ul> <li><strong>Auto Focus Keyword for SEO</strong> creates the focus keyword signal</li> <li><strong>Automatic Internal Links for SEO</strong> uses that signal to build links</li> </ul> <p>Pipeline overview: <a href="https://autolinksforseo.com/pipeline" rel="nofollow ugc">https://autolinksforseo.com/pipeline</a></p> <h4>Compatibility</h4> <p>Automatic Internal Links supports focus keyword data from:</p> <ul> <li><strong>Yoast SEO</strong></li> <li><strong>Rank Math</strong></li> <li><strong>All in One SEO (AIOSEO)</strong></li> </ul> <p>Known limitations:</p> <ul> <li><strong>ACF:</strong> not supported for content processing</li> <li><strong>WPML / Polylang:</strong> partially supported; identical words across languages may still be ambiguous</li> <li><strong>WooCommerce products:</strong> Pro</li> <li><strong>Taxonomy / category pages:</strong> not covered by default</li> </ul> <h4>Performance profile</h4> <p>Automatic Internal Links is designed to remain practical on real WordPress sites.</p> <p>The plugin includes caching and batched workflows to reduce repeated heavy operations. Actual impact depends on content volume, matching rules, hosting, theme output, and publishing activity.</p> <p>A cautious internal linking setup is usually better than an aggressive one. In most cases, a small number of relevant links per page is preferable.</p> <h4>Links</h4> <ul> <li><a href="https://autolinksforseo.com/internal-links" rel="nofollow ugc">Official documentation</a></li> <li><a href="https://autolinksforseo.com/pricing" rel="nofollow ugc">Pricing and plans</a></li> <li><a href="https://autolinksforseo.com/compatibility" rel="nofollow ugc">Compatibility and FAQ</a></li> <li><a href="https://autolinksforseo.com/pipeline" rel="nofollow ugc">Pipeline overview</a></li> <li><a href="https://autolinksforseo.com/guides/changelog-ail" rel="nofollow ugc">Full changelog</a></li> </ul> <h4>About the publisher</h4> <p>Automatic Internal Links for SEO is developed by <a href="https://pagup.com/" rel="nofollow ugc">Pagup</a>, a digital readability firm based in Quebec, Canada.</p> <p>Internal linking is a structural layer of digital readability. It tells search engines and AI systems how your pages relate to each other, which pages carry authority, and how your content is organized. Without coherent internal links, even well-written content remains structurally isolated — a problem known as <a href="https://pagup.com/en/glossary/canonical-fragility/" rel="nofollow ugc">canonical fragility</a>.</p> <p>This plugin automates the creation and maintenance of internal links so that your site&#8217;s structure remains coherent as your content grows.</p> <h4>Part of the Pagup ecosystem</h4> <ul> <li><a href="https://pagup.com/" rel="nofollow ugc">pagup.com</a> — Digital readability firm. Diagnostic, semantic architecture, AI governance.</li> <li><a href="https://gautierdorval.com/" rel="nofollow ugc">gautierdorval.com</a> — Doctrine, canonical definitions, interpretive governance research.</li> <li><a href="https://interpretive-governance.org/" rel="nofollow ugc">interpretive-governance.org</a> — Formal versioned standard for interpretive governance.</li> <li><a href="https://autolinksforseo.com/" rel="nofollow ugc">autolinksforseo.com</a> — Documentation and resources for Automatic Internal Links.</li> </ul>
WordPress Plugin DirectoryWordPress Plugin Directory
31.2K