Executive brief
Broken Link Checker is a popular WordPress plugin used to monitor and fix internal and external links on a website. A security vulnerability in this plugin could allow an attacker with high-level administrative access to perform unauthorized database queries. This could lead to the exposure of sensitive site information or disruption of database operations.
Technical details
A blind SQL injection vulnerability exists in the WPMU DEV Broken Link Checker plugin for WordPress due to improper neutralization of special elements in SQL commands. The flaw affects versions up to and including 2.4.7. An attacker with high privileges (such as an Editor or Administrator) can exploit this via network requests to interact directly with the underlying database. While the vulnerability requires authentication, the 'Blind' nature of the injection allows for the extraction of sensitive data through inference. The issue is addressed in version 2.4.8.
Affected products
- WPMU DEV Broken Link Checker <= 2.4.7
Timeline
- 2026-02-24: other: Vulnerability reported by researcher daroo
- 2026-03-26: patched: Patch released in version 2.4.8
- 2026-04-08: disclosed: CVE published