The Broken Link Checker WordPress plugin before 2.4.2 does not validate a the link URLs before making a request to them, which could allow admin users to perform SSRF attack, for example on a multisite installation.
History

Thu, 26 Dec 2024 06:15:00 +0000

Type Values Removed Values Added
Description The Broken Link Checker WordPress plugin before 2.4.2 does not validate a the link URLs before making a request to them, which could allow admin users to perform SSRF attack, for example on a multisite installation.
Title Broken Link Checker < 2.4.2 - Admin+ SSRF
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2024-12-26T06:00:05.613Z

Updated: 2024-12-26T06:00:05.613Z

Reserved: 2024-11-05T20:04:50.936Z

Link: CVE-2024-10903

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2024-12-26T06:15:05.397

Modified: 2024-12-26T06:15:05.397

Link: CVE-2024-10903

cve-icon Redhat

No data.