Junglewise Threat Intelligence

CVE-2026-75528: WordPress Broken Link Checker stored XSS in link log

CVE-2026-75528 · Severity: high · CVSS 7.2 · Published 2026-09-02

Vendors: Wordpress.

Executive brief

The Broken Link Checker plugin for WordPress is used to monitor and report broken links on websites. An unauthenticated attacker can inject malicious JavaScript code through WordPress comment fields that gets stored in the plugin's link log; when site administrators review the log, the injected code executes, potentially compromising their session or enabling further attacks on site visitors.

Technical details

This is a stored cross-site scripting (XSS) vulnerability caused by insufficient input sanitization and output escaping in the Broken Link Checker plugin's link log functionality. An attacker submits a malicious URL via the WordPress comment author URL field; when an administrator performs the plugin's dismiss-and-recheck workflow, the attacker's HTTP server responds with a redirect to a URL containing HTML/JavaScript payload that is stored verbatim in the link log database. The stored payload executes in the administrator's browser when they access the log, requiring no user interaction beyond normal plugin operation. The vulnerability affects all versions up to and including 2.4.13, and patches or workarounds have not yet been confirmed.

Affected products

  • WordPress Broken Link Checker up to 2.4.13

Timeline

  • 2026-09-02: disclosed

References