Impact
The Broken Link Notifier WordPress plugin, in all releases before 2.0.0.1, fails to re‑validate the target of HTTP redirects when checking links. Because the internal‑address filter on the plugin is bypassed, an unauthenticated attacker can supply a crafted link that redirects the WordPress server to an arbitrary internal address. The web server will then send a request to that address, enabling the attacker to probe or interact with internal services that are normally inaccessible from the public internet.
Affected Systems
The vulnerability affects the Broken Link Notifier plugin for WordPress. All plugin releases from version 1.3.1 up to, but not including, 2.0.0.1 are impacted. No other vendor or product information is available.
Risk and Exploitability
The CVSS score is not provided in the available data, and the EPSS score is not available, so the exact exploitation probability cannot be quantified. However, the plugin is publicly accessible to all users of the WordPress site, and the lack of authentication for the incident means the exploit can be performed without any credentials. The vulnerability is listed as not present in the CISA KEV catalog, suggesting the exploit is not currently known to be actively used, but the internal‑service access granted could be leveraged to up‑turn a future exploit or to abuse other vulnerabilities within the internal network.
OpenCVE Enrichment