GHSA-vxvw-9xhx-r2mfMediumCVSS 5.8

The Broken Link Notifier WordPress plugin before 2.0.0.1 does not re-validate the destination of...

Published
September 30, 2026
Last Modified
September 30, 2026

🔗 CVE IDs covered (1)

📋 Description

The Broken Link Notifier WordPress plugin before 2.0.0.1 does not re-validate the destination of redirects when checking links, allowing unauthenticated attackers to bypass its internal-address filter and make the server send requests to internal services.

🔗 References (3)