PT-2024-16634 · WordPress · Broken Link Checker
Carlos Flores
·
Published
2024-12-26
·
Updated
2024-12-30
·
CVE-2024-10903
CVSS v3.1
4.7
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Broken Link Checker WordPress plugin versions prior to 2.4.2
Description
The issue arises from the plugin's failure to validate link URLs before making requests to them. This could allow admin users to perform Server-Side Request Forgery (SSRF) attacks, particularly in multisite installations. SSRF is a type of attack where an attacker can trick a server into making requests to internal or external resources, potentially leading to unauthorized access or data exposure.
Recommendations
For versions prior to 2.4.2, update to version 2.4.2 or later to resolve the issue. As a temporary workaround, consider restricting the use of the Broken Link Checker plugin in multisite installations until the update is applied. Additionally, restrict access to the plugin's functionality for non-admin users to minimize the risk of exploitation.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Broken Link Checker