Impact
The Broken Link Notifier plugin for WordPress allows an unauthenticated attacker to trigger the ajax_blinks() handler, causing the web application to send HTTP requests to arbitrary destinations. This Server‑Side Request Forgery enables the attacker to interrogate or change data from internal services, potentially exposing sensitive information or compromising the integrity of internal resources. The weakness is identified as CWE‑918, representing a serious confidentiality, integrity, and availability risk.
Affected Systems
The vulnerability affects the WordPress plugin Broken Link Notifier from vendor apos37 in all releases up to and including version 1.3.0. Any WordPress site that has a version of this plugin in that range is potentially vulnerable.
Risk and Exploitability
With a CVSS score of 7.2, the vulnerability is considered high severity. The EPSS score of < 1% indicates a very low likelihood that exploitation will occur, and the issue is not yet listed in the CISA KEV catalog. Based on the description, the attack vector is likely an unauthenticated HTTP request to the plugin’s AJAX endpoint, allowing attackers to trigger arbitrary internal calls from the web application.
OpenCVE Enrichment
EUVD