CVE-2024-10903: Managewp Broken Link Checker
Medium severity, CVSS 4.7. EPSS: 0.4% chance of exploitation in the next 30 days.
The Broken Link Checker WordPress plugin before 2.4.2 does not validate a the link URLs before making a request to them, which could allow admin users to perform SSRF attack, for example on a multisite installation.
Affected products
- Managewp Broken Link Checker: before 2.4.2 (fixed in 2.4.2)
Published 2024-12-26. Last modified 2026-06-17.