Impact
The vulnerability allows an unauthenticated attacker to place arbitrary JavaScript into the Comment Author URL field of a comment. When an administrator dismisses and re‑checks the link, the unsanitized URL is saved in the link log. Subsequent visitors who load the log entry receive the attacker’s payload, which executes in the victim’s browser and can steal session cookies, deface content, or perform other client‑side actions.
Affected Systems
WordPress sites that have the Broken Link Checker plugin by WPMU DEV installed in version 2.4.13 or any earlier release are affected. The vulnerability exists in all builds up to and including 2.4.13, regardless of additional components or integrations.
Risk and Exploitability
The CVSS score of 7.2 indicates a high impact if exploitation succeeds. Because the flaw requires no authentication to inject the payload but does require the administrator to dismiss the link to persist the injection, an attacker would need to have the opportunity to convince an admin to perform that action. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting that widespread, automated exploitation has not yet been observed. Nonetheless, the stored‑XSS nature of the flaw means that any user who visits affected pages could be compromised.
OpenCVE Enrichment