Executive brief
Broken Link Checker is a WordPress plugin that validates links on websites. A Server Side Request Forgery vulnerability allows authenticated editors to force the server to make arbitrary network requests, potentially exposing data from internal systems behind the firewall or interacting with internal services. Exploitation requires editor-level WordPress permissions.
Technical details
The vulnerability is a Server Side Request Forgery (SSRF) in the Broken Link Checker WordPress plugin versions 2.4.14 and earlier. An attacker with editor privileges can craft requests that cause the plugin to make unintended server-side HTTP connections to internal systems, services, or cloud metadata endpoints. The attack vector requires authentication (editor role) and network access to the WordPress site. An attacker can bypass network segmentation and leak sensitive data from internal systems or cloud infrastructure. The vulnerability was patched in version 2.4.14.1; users should update immediately.
Affected products
- WPMU DEV Broken Link Checker <= 2.4.14
Timeline
- 2026-08-25: disclosed: Reported to Patchstack by Ananda Dhakal
- 2026-09-02: advisory: Published by Patchstack
- 2026-09-02: patched: Fix available in version 2.4.14.1