Broken Link Notifier [broken-link-notifier] <= 1.3.5 (unfixed)
unknown
[en] Missing Authorization vulnerability in PluginRx Broken Link Notifier broken-link-notifier allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Broken Link Notifier: from n/a through <= 1.3.5.
- Affected:
- up to 1.3.5
- Fix:
- No patched version reported
- Disclosed:
- Feb 19, 2026
CVE-2026-25408 on NVD →
Broken Link Notifier <= 1.3.5 - Missing Authorization
medium
The Broken Link Notifier plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.3.5. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 1.3.5
- Fixed in:
- 1.3.6
- Disclosed:
- Jan 29, 2026
CVE-2026-25408 on NVD →
Broken Link Notifier <= 1.3.0 - Unauthenticated Server-Side Request Forgery
high
The Broken Link Notifier plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.3.0 via the ajax_blinks() function which ultimately calls the check_url_status_code() function. This makes it possible for unauthenticated attackers to make web requests to arbitrary locati...
- CVSS:
- 7.2
- Affected:
- up to 1.3.0
- Fixed in:
- 1.3.1
- Disclosed:
- Jul 10, 2025
CVE-2025-6851 on NVD →
Broken Link Notifier <= 1.3.0 - Authenticated (Contributor+) CSV Injection
medium
The Broken Link Notifier plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 1.3.0 via broken links that are later exported. This makes it possible for authenticated attackers, with Contributor-level access and above, to embed untrusted input into exported CSV files, which can resu...
- CVSS:
- 4.1
- Affected:
- up to 1.3.0
- Fixed in:
- 1.3.1
- Disclosed:
- Jul 10, 2025
CVE-2025-6838 on NVD →
Broken Link Notifier [broken-link-notifier] < 1.3.1
unknown
- Affected:
- up to 1.3.1
- Fixed in:
- 1.3.1
CVE-2025-6851 on NVD →
Broken Link Notifier [broken-link-notifier] < 1.3.1
unknown
- Affected:
- up to 1.3.1
- Fixed in:
- 1.3.1
CVE-2025-6838 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database