The Broken Link Checker WordPress plugin before 2.4.2 does not validate a the link URLs before making a request to them, which could allow admin users to perform SSRF attack, for example on a multisite installation.

Project Subscriptions

Vendors Products
Managewp Subscribe
Broken Link Checker Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 14 May 2025 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Managewp
Managewp broken Link Checker
Weaknesses CWE-918
CPEs cpe:2.3:a:managewp:broken_link_checker:*:*:*:*:*:wordpress:*:*
Vendors & Products Managewp
Managewp broken Link Checker

Mon, 30 Dec 2024 18:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 26 Dec 2024 06:15:00 +0000

Type Values Removed Values Added
Description The Broken Link Checker WordPress plugin before 2.4.2 does not validate a the link URLs before making a request to them, which could allow admin users to perform SSRF attack, for example on a multisite installation.
Title Broken Link Checker < 2.4.2 - Admin+ SSRF
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2024-12-30T17:13:04.285Z

Reserved: 2024-11-05T20:04:50.936Z

Link: CVE-2024-10903

cve-icon Vulnrichment

Updated: 2024-12-30T17:12:58.042Z

cve-icon NVD

Status : Analyzed

Published: 2024-12-26T06:15:05.397

Modified: 2025-05-14T15:04:30.627

Link: CVE-2024-10903

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses