WordPress · Broken Link Notifier · CVE-2026-97316
**Name of the Vulnerable Software and Affected Versions**
Broken Link Notifier WordPress plugin versions prior to 2.0.0.1
**Description**
The plugin fails to re-validate the destination of redirects during link checks. This allows unauthenticated attackers to bypass the internal-address filter, enabling the server to send unauthorized requests to internal services. This is a Server-Side Request Forgery (SSRF) issue, where an attacker forces the server to perform requests on their behalf.
**Recommendations**
Update the Broken Link Notifier WordPress plugin to version 2.0.0.1 or later.