Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-21125 | The Broken Link Notifier plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.3.0 via the ajax_blinks() function which ultimately calls the check_url_status_code() function. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 17 Jul 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pluginrx
Pluginrx broken Link Notifier |
|
| CPEs | cpe:2.3:a:pluginrx:broken_link_notifier:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Pluginrx
Pluginrx broken Link Notifier |
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 11 Jul 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
Fri, 11 Jul 2025 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Broken Link Notifier plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.3.0 via the ajax_blinks() function which ultimately calls the check_url_status_code() function. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. | |
| Title | Broken Link Notifier <= 1.3.0 - Unauthenticated Server-Side Request Forgery | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-07-11T15:37:17.142Z
Reserved: 2025-06-27T18:57:21.368Z
Link: CVE-2025-6851
Updated: 2025-07-11T15:33:21.796Z
Status : Analyzed
Published: 2025-07-11T09:15:25.370
Modified: 2025-07-17T13:11:21.863
Link: CVE-2025-6851
No data.
OpenCVE Enrichment
Updated: 2025-07-12T23:05:37Z
EUVD