Impact
The Broken Link Notifier plugin contains a CSV Injection flaw that allows authenticated users who have Contributor-level or higher privileges to embed malicious spreadsheet formulas into exported CSV files. When a user opens such a file in a spreadsheet application that evaluates formulas, the injected content can execute arbitrary code on the local system. The vulnerability is classified as CWE‑1236.
Affected Systems
All releases of the Broken Link Notifier plugin for WordPress up to and including version 1.3.0 are affected. The plugin is released by vendor apos37 and is distributed through the WordPress plugin repository.
Risk and Exploitability
The CVSS base score of 4.1 indicates a moderate severity that requires authentication. The EPSS score is less than 1%, implying a low likelihood of widespread exploitation, and the issue is not listed in the CISA KEV catalog. Attackers must first use the exporter to create the CSV, then persuade a user with a vulnerable spreadsheet application to open the file. Successful exploitation results in code execution on the local machine only when the file is processed.
OpenCVE Enrichment
EUVD