Impact
The vulnerability is a server‑side request forgery that allows an attacker to cause the WordPress server to fetch arbitrary URLs, potentially exposing internal resources or enabling further exploitation. The weakness is classified as CWE‑918. The impact is data leakage or unauthorized access to internal services through outbound HTTP requests triggered by the plugin.
Affected Systems
The affected product is the WordPress Broken Link Checker plugin by WPMU DEV. Versions up to and including 2.4.14 are impacted; no version beyond 2.4.14 is listed as affected.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity. The EPSS score is not reported, so the likelihood of exploitation cannot be quantified from the available data. The vulnerability is not listed in CISA’s KEV catalog, suggesting no widespread public exploitation yet. The likely attack path involves an attacker supplying a crafted link to the plugin, which then causes the server to perform a request to a target of the attacker’s choosing. Proper mitigation is therefore recommended to prevent accidental exposure of internal endpoints.
OpenCVE Enrichment