CVE-2026-97316: Unknown Broken Link Notifier

Medium severity, CVSS 5.8. EPSS: 0.2% chance of exploitation in the next 30 days.

The Broken Link Notifier WordPress plugin before 2.0.0.1 does not re-validate the destination of redirects when checking links, allowing unauthenticated attackers to bypass its internal-address filter and make the server send requests to internal services.

Affected products

  • Unknown Broken Link Notifier: from 1.3.1, before 2.0.0.1 (fixed in 2.0.0.1)

Published 2026-09-30. Last modified 2026-09-30.