Skip to main content

CVE-2025-1264: AIOSEO Broken Link Checker SQL Injection

CVE-2025-1264 is a SQL injection flaw in the AIOSEO Broken Link Checker plugin for WordPress affecting versions up to 1.2.3. Authenticated attackers with Contributor access can extract sensitive database information. This article covers technical details, affected versions, impact assessment, and mitigation strategies.

Published:

CVE-2025-1264 Overview

CVE-2025-1264 is a SQL Injection vulnerability in the Broken Link Checker by AIOSEO WordPress plugin, affecting all versions up to and including 1.2.3. The flaw resides in the handling of the orderBy parameter, which is neither sufficiently escaped nor prepared before being concatenated into an SQL query. Authenticated users with Contributor-level access or higher can append additional SQL statements to existing queries and extract sensitive data from the WordPress database. The vulnerability is tracked as [CWE-89] and was reported through the Wordfence Threat Intelligence program.

Critical Impact

Authenticated attackers with Contributor privileges can exfiltrate arbitrary data from the WordPress database, including user credentials, session tokens, and private post content.

Affected Products

  • Broken Link Checker by AIOSEO – Easily Fix/Monitor Internal and External links (WordPress plugin)
  • All plugin versions ≤ 1.2.3
  • WordPress installations with Contributor-level or higher user accounts

Discovery Timeline

  • 2025-04-06 - CVE-2025-1264 published to the National Vulnerability Database (NVD)
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-1264

Vulnerability Analysis

The plugin exposes an authenticated REST endpoint used to render the broken-link status table. The endpoint accepts an orderBy parameter that is passed directly into a query builder responsible for constructing the ORDER BY clause of a SELECT statement. Because WordPress core's $wpdb->prepare() does not sanitize identifiers such as column names, the plugin must implement allowlisting or explicit escaping. That protection is absent.

As a result, the parameter value is concatenated into the SQL string. Attackers can inject a UNION-based or stacked subquery expression through orderBy to alter the query semantics. Because Contributor accounts are commonly created through open registration or granted to guest writers, the attacker prerequisites are low for many WordPress deployments.

Root Cause

The root cause is improper neutralization of special elements used in an SQL command ([CWE-89]). The relevant plugin code paths in app/Api/Api.php, app/Api/LinkStatusTable.php, and app/Core/Database.php build the query string from the client-supplied orderBy value without an allowlist of permitted column names and without wrapping the value in a prepared statement placeholder suitable for identifiers.

Attack Vector

Exploitation requires a valid authenticated session with Contributor privileges or higher and network reachability to the WordPress admin API. The attacker issues a crafted request to the plugin's link-status endpoint, placing malicious SQL fragments in the orderBy query parameter. Because the injection point sits inside the ORDER BY clause, attackers typically leverage subselect expressions such as (CASE WHEN ... THEN ... ELSE ... END) or (SELECT ...) to perform boolean-based or time-based blind extraction of database contents.

Refer to the Wordfence Vulnerability Report and the WordPress Plugin Change Set for the specific code paths and remediation diff.

Detection Methods for CVE-2025-1264

Indicators of Compromise

  • HTTP requests to the plugin's REST namespace containing an orderBy parameter with SQL keywords such as SELECT, UNION, SLEEP, CASE WHEN, or comment sequences (--, /*).
  • Abnormally long response times to plugin API endpoints, consistent with time-based blind SQL injection.
  • Web server logs showing repeated requests to broken-link-checker-seo endpoints from a single Contributor account within a short window.
  • Unexpected reads from wp_users, wp_usermeta, or wp_options tables originating from the WordPress database user.

Detection Strategies

  • Deploy WordPress-aware web application firewall (WAF) rules that block non-allowlisted values in the orderBy parameter for the affected plugin routes.
  • Enable MySQL general or slow query logging temporarily and alert on ORDER BY clauses containing subqueries or conditional expressions.
  • Correlate authentication events for Contributor-level accounts with plugin API access patterns to surface reconnaissance behavior.

Monitoring Recommendations

  • Monitor creation of new Contributor, Author, or Editor accounts, especially through open registration.
  • Alert on database errors returned in plugin API responses, which often accompany SQL injection probing.
  • Track outbound data volumes from the WordPress host to detect bulk extraction following successful injection.

How to Mitigate CVE-2025-1264

Immediate Actions Required

  • Update the Broken Link Checker by AIOSEO plugin to the version published in changeset 3263416, which addresses the orderBy handling.
  • Audit all WordPress accounts with Contributor privileges or higher and disable unused or untrusted accounts.
  • Rotate WordPress secret keys in wp-config.php and reset passwords for privileged users if exploitation is suspected.

Patch Information

The vendor addressed the vulnerability in the release following version 1.2.3, as reflected in the WordPress Plugin Change Set. The fix restricts the orderBy parameter to an allowlist of valid column identifiers before it is used in query construction. Administrators should install the patched version through the WordPress plugin updater or download it from the WordPress Plugin Overview page.

Workarounds

  • Deactivate and remove the Broken Link Checker by AIOSEO plugin until the patched version can be installed.
  • Restrict access to the WordPress admin and REST API using IP allowlists or authentication proxies while the plugin remains vulnerable.
  • Temporarily downgrade all non-administrative accounts below Contributor level to remove the authentication precondition for exploitation.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.