Description
The Broken Link Notifier WordPress plugin before 2.0.0.1 does not re-validate the destination of redirects when checking links, allowing unauthenticated attackers to bypass its internal-address filter and make the server send requests to internal services.
Published: 2026-09-30
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Remote Server‑Side Request Forgery
Action: Apply Patch
AI Analysis

Impact

The Broken Link Notifier WordPress plugin, in all releases before 2.0.0.1, fails to re‑validate the target of HTTP redirects when checking links. Because the internal‑address filter on the plugin is bypassed, an unauthenticated attacker can supply a crafted link that redirects the WordPress server to an arbitrary internal address. The web server will then send a request to that address, enabling the attacker to probe or interact with internal services that are normally inaccessible from the public internet.

Affected Systems

The vulnerability affects the Broken Link Notifier plugin for WordPress. All plugin releases from version 1.3.1 up to, but not including, 2.0.0.1 are impacted. No other vendor or product information is available.

Risk and Exploitability

The CVSS score is not provided in the available data, and the EPSS score is not available, so the exact exploitation probability cannot be quantified. However, the plugin is publicly accessible to all users of the WordPress site, and the lack of authentication for the incident means the exploit can be performed without any credentials. The vulnerability is listed as not present in the CISA KEV catalog, suggesting the exploit is not currently known to be actively used, but the internal‑service access granted could be leveraged to up‑turn a future exploit or to abuse other vulnerabilities within the internal network.

Generated by OpenCVE AI on September 30, 2026 at 12:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Broken Link Notifier plugin to version 2.0.0.1 or later, if such a release is available.
  • If an upgrade cannot be performed immediately, disable or uninstall the plugin while a more secure alternative is chosen.
  • Restrict outbound HTTP connections from the web server to internal addresses using firewall rules or other network segmentation to prevent the server from reaching internal services via redirects.

Generated by OpenCVE AI on September 30, 2026 at 12:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-918

Wed, 30 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Broken Link Notifier WordPress plugin before 2.0.0.1 does not re-validate the destination of redirects when checking links, allowing unauthenticated attackers to bypass its internal-address filter and make the server send requests to internal services.
Title Broken Link Notifier 1.3.1 - 2.0.0 - Unauthenticated SSRF via Redirect Bypass
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-30T06:00:26.188Z

Reserved: 2026-09-24T11:27:38.895Z

Link: CVE-2026-97316

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-30T06:17:11.137

Modified: 2026-09-30T06:17:11.137

Link: CVE-2026-97316

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T13:00:16Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)