Broken Link Checker | Finder <= 2.5.0 - Authenticated (Author+) Blind Server-Side Request Forgery
medium
The Broken Link Checker | Finder plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 2.5.0 via the 'moblc_check_link' function. This makes it possible for authenticated attackers, with Author-level access and above, to make web requests to arbitrary locations or...
- CVSS:
- 5.4
- Affected:
- up to 2.5.0
- Fixed in:
- 2.5.1
- Disclosed:
- Dec 18, 2024
CVE-2024-12121 on NVD →
Broken Link Checker | Finder <= 2.4.2 - Missing Authorization via moblc_auth_save_settings
medium
The Broken Link Checker | Finder plugin for WordPress is vulnerable to modification of data due to a missing capability check on the moblc_auth_save_settings function in versions up to, and including, 2.4.2. This makes it possible for unauthenticated attackers to dismiss admin notifications
- CVSS:
- 5.3
- Affected:
- up to 2.4.2
- Fixed in:
- 2.5.0
- Disclosed:
- Oct 16, 2023
CVE-2023-46082 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database