Broken Link Manager [broken-link-manager] <= 0.6.5 (unfixed + closed)
unknown
[en] The Broken Link Manager WordPress plugin through 0.6.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
- Affected:
- up to 0.6.5
- Fix:
- No patched version reported
- Disclosed:
- Nov 24, 2025
CVE-2025-12629 on NVD →
Broken Link Manager <= 0.6.5 - Reflected Cross-Site Scripting
medium
The Broken Link Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 0.6.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successf...
- CVSS:
- 6.1
- Affected:
- up to 0.6.5
- Fix:
- No patched version reported
- Disclosed:
- Nov 3, 2025
CVE-2025-12629 on NVD →
Broken Link Manager [broken-link-manager] <= 0.6.5 (unfixed + closed)
unknown
[en] The Broken Link Manager WordPress plugin through 0.6.5 does not sanitise, validate or escape the url GET parameter before using it in a SQL statement when retrieving an URL to edit, leading to an authenticated SQL injection issue
- Affected:
- up to 0.6.5
- Fix:
- No patched version reported
- Disclosed:
- Aug 23, 2021
CVE-2021-24550 on NVD →
Broken Link Manager <= 0.6.5 - Authenticated (Admin+) SQL Injection
high
The Broken Link Manager WordPress plugin through 0.6.5 does not sanitise, validate or escape the url GET parameter before using it in a SQL statement when retrieving an URL to edit, leading to an authenticated SQL injection issue
- CVSS:
- 7.2
- Affected:
- up to 0.6.5
- Fix:
- No patched version reported
- Disclosed:
- Jul 24, 2021
CVE-2021-24550 on NVD →
Broken Link Manager [broken-link-manager] < 0.5.0
unknown
[en] The broken-link-manager plugin before 0.5.0 for WordPress has wpslDelURL or wpslEditURL SQL injection via the url parameter.
- Affected:
- up to 0.5.0
- Fixed in:
- 0.5.0
- Disclosed:
- Oct 10, 2019
CVE-2015-9467 on NVD →
Broken Link Manager [broken-link-manager] < 0.5.0
unknown
[en] The broken-link-manager plugin 0.4.5 for WordPress has XSS via the page parameter in a delURL action.
- Affected:
- up to 0.5.0
- Fixed in:
- 0.5.0
- Disclosed:
- Oct 10, 2019
CVE-2015-9468 on NVD →
Broken Link Manager [broken-link-manager] < 0.6.0
unknown
[en] The broken-link-manager plugin before 0.6.0 for WordPress has XSS via the HTTP Referer or User-Agent header to a URL that does not exist.
- Affected:
- up to 0.6.0
- Fixed in:
- 0.6.0
- Disclosed:
- Oct 7, 2019
CVE-2015-9453 on NVD →
Broken Link Manager < 0.6.0 - Cross-Site Scripting
medium
The broken-link-manager plugin before 0.6.0 for WordPress has XSS via the HTTP Referer or User-Agent header to a URL that does not exist.
- CVSS:
- 6.1
- Affected:
- up to 0.6.0
- Fixed in:
- 0.6.0
- Disclosed:
- Jul 16, 2015
CVE-2015-9453 on NVD →
Broken Link Manager [broken-link-manager] < 0.6.0 (closed)
unknown
Because of this vulnerability, unauthenticated attackers can inject malicious HTML or JavaScript.
Update the plugin.
- Affected:
- up to 0.6.0
- Fixed in:
- 0.6.0
- Disclosed:
- Jul 16, 2015
Broken Link Manager < 0.5.0 - SQL Injection
critical
The broken-link-manager plugin before 0.5.0 for WordPress has wpslDelURL or wpslEditURL SQL injection via the url parameter.
- CVSS:
- 9.8
- Affected:
- up to 0.5.0
- Fixed in:
- 0.5.0
- Disclosed:
- Jul 4, 2015
CVE-2015-9467 on NVD →
Broken Link Manager <= 0.4.5 - Cross-Site Scripting
medium
The broken-link-manager plugin 0.4.5 for WordPress has XSS via the page parameter in a delURL action.
- CVSS:
- 6.1
- Affected:
- up to 0.4.5
- Fixed in:
- 0.5.0
- Disclosed:
- Jul 4, 2015
CVE-2015-9468 on NVD →
Broken Link Manager [broken-link-manager] < 0.5.0 (closed)
unknown
Because of this vulnerability, unauthenticated remote attackers can execute arbitrary SQL commands and inject malicious javascript.
Update the plugin.
- Affected:
- up to 0.5.0
- Fixed in:
- 0.5.0
- Disclosed:
- Jul 4, 2015
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database