PT-2024-16634 · WordPress · Broken Link Checker

Carlos Flores

·

Published

2024-12-26

·

Updated

2024-12-30

·

CVE-2024-10903

CVSS v3.1

4.7

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Broken Link Checker WordPress plugin versions prior to 2.4.2
Description The issue arises from the plugin's failure to validate link URLs before making requests to them. This could allow admin users to perform Server-Side Request Forgery (SSRF) attacks, particularly in multisite installations. SSRF is a type of attack where an attacker can trick a server into making requests to internal or external resources, potentially leading to unauthorized access or data exposure.
Recommendations For versions prior to 2.4.2, update to version 2.4.2 or later to resolve the issue. As a temporary workaround, consider restricting the use of the Broken Link Checker plugin in multisite installations until the update is applied. Additionally, restrict access to the plugin's functionality for non-admin users to minimize the risk of exploitation.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2024-10903

Affected Products

Broken Link Checker