CVE-2019-16521: XSS
The broken-link-checker plugin through 1.11.8 for WordPress (aka Broken Link Checker) is susceptible to Reflected XSS due to improper encoding and insertion of an HTTP GET parameter into HTML. The filter function on the page listing all detected broken links can be exploited by providing an XSS payload in the sfilter GET parameter in a filterid=search request. NOTE: this is an end-of-life product.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-16521 vulnerability?
CVE-2019-16521 is a vulnerability in the Broken Link Checker plugin for WordPress that allows for Reflected XSS attacks due to improper encoding and insertion of an HTTP GET parameter into HTML.
What is the severity of CVE-2019-16521?
The severity of CVE-2019-16521 is medium with a CVSS score of 6.1.
How does CVE-2019-16521 affect WordPress?
CVE-2019-16521 affects WordPress through the Broken Link Checker plugin, version 1.11.8.
How can CVE-2019-16521 be exploited?
CVE-2019-16521 can be exploited by providing an XSS payload in the filter function on the page listing all detected broken links.
Is there a fix for CVE-2019-16521?
Yes, a fix for CVE-2019-16521 is available. It is recommended to update the Broken Link Checker plugin to version 1.11.9 or later.