CVE-2026-97316: Unknown Broken Link Notifier
Medium severity, CVSS 5.8. EPSS: 0.2% chance of exploitation in the next 30 days.
The Broken Link Notifier WordPress plugin before 2.0.0.1 does not re-validate the destination of redirects when checking links, allowing unauthenticated attackers to bypass its internal-address filter and make the server send requests to internal services.
Affected products
- Unknown Broken Link Notifier: from 1.3.1, before 2.0.0.1 (fixed in 2.0.0.1)
Published 2026-09-30. Last modified 2026-09-30.