rootpwn

medium · CVSS v3 5.8 · EPSS 0.00145

CVE-2026-97316

The Broken Link Notifier WordPress plugin (v<2.0.0.1) fails to re‑validate redirect destinations, letting unauthenticated users force the se

Overview

The Broken Link Notifier WordPress plugin (v<2.0.0.1) fails to re‑validate redirect destinations, letting unauthenticated users force the server to request internal services. This flaw can expose internal network resources and potentially leak sensitive data. It is a medium‑severity vulnerability with a low EPSS score.

Description

The Broken Link Notifier WordPress plugin before 2.0.0.1 does not re-validate the destination of redirects when checking links, allowing unauthenticated attackers to bypass its internal-address filter and make the server send requests to internal services.

Impact

Confidentiality: internal services may be accessed or enumerated. Integrity: internal requests could be manipulated. Availability: repeated requests could strain internal resources. Site administrators and internal network owners are directly impacted.

Remediation

Update the plugin to version 2.0.0.1 or later. If an update is not possible, disable the redirect feature or restrict outbound requests from the plugin. Monitor outbound traffic for unexpected internal requests and apply network segmentation or firewall rules to block unauthorized internal access.

Risk context

Severity is medium (CVSS 5.8) and the EPSS score is 0.00145, indicating a low likelihood of exploitation but still requiring timely patching to prevent potential internal exposure.

Affected products

  • WordPress
  • Broken Link Notifier

Scores

Severity
medium
CVSS v2
6.4
CVSS v3
5.8
CVSS v4
—
EPSS
0.00145

WordPress plugin internal-redirect outbound-requests CVE-2026-97316 vulnerability mitigation

← All CVEs