medium · CVSS v3 5.8 · EPSS 0.00145
CVE-2026-97316
The Broken Link Notifier WordPress plugin (v<2.0.0.1) fails to re‑validate redirect destinations, letting unauthenticated users force the se
Overview
The Broken Link Notifier WordPress plugin (v<2.0.0.1) fails to re‑validate redirect destinations, letting unauthenticated users force the server to request internal services. This flaw can expose internal network resources and potentially leak sensitive data. It is a medium‑severity vulnerability with a low EPSS score.
Description
The Broken Link Notifier WordPress plugin before 2.0.0.1 does not re-validate the destination of redirects when checking links, allowing unauthenticated attackers to bypass its internal-address filter and make the server send requests to internal services.
Impact
Confidentiality: internal services may be accessed or enumerated. Integrity: internal requests could be manipulated. Availability: repeated requests could strain internal resources. Site administrators and internal network owners are directly impacted.
Remediation
Update the plugin to version 2.0.0.1 or later. If an update is not possible, disable the redirect feature or restrict outbound requests from the plugin. Monitor outbound traffic for unexpected internal requests and apply network segmentation or firewall rules to block unauthorized internal access.
Risk context
Severity is medium (CVSS 5.8) and the EPSS score is 0.00145, indicating a low likelihood of exploitation but still requiring timely patching to prevent potential internal exposure.
Affected products
- WordPress
- Broken Link Notifier
Scores
- Severity
- medium
- CVSS v2
- 6.4
- CVSS v3
- 5.8
- CVSS v4
- —
- EPSS
- 0.00145