PT-2026-103048 · WordPress · Broken Link Notifier
CVSS v3.1
5.8
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Broken Link Notifier WordPress plugin versions prior to 2.0.0.1
Description
The plugin fails to re-validate the destination of redirects during link checks. This allows unauthenticated attackers to bypass the internal-address filter, enabling the server to send unauthorized requests to internal services. This is a Server-Side Request Forgery (SSRF) issue, where an attacker forces the server to perform requests on their behalf.
Recommendations
Update the Broken Link Notifier WordPress plugin to version 2.0.0.1 or later.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Broken Link Notifier