CVE-2024-10903: Broken Link Checker < 2.4.2 - Admin+ SSRF
The Broken Link Checker WordPress plugin before 2.4.2 does not validate a the link URLs before making a request to them, which could allow admin users to perform SSRF attack, for example on a multisite installation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10903?
CVE-2024-10903 has a medium severity rating due to its potential for SSRF attacks that could affect WordPress multisite installations.
How do I fix CVE-2024-10903?
To mitigate the risks associated with CVE-2024-10903, update the Broken Link Checker WordPress plugin to version 2.4.2 or later.
Who is affected by CVE-2024-10903?
Any WordPress multisite installations using the Broken Link Checker plugin prior to version 2.4.2 are vulnerable to CVE-2024-10903.
What type of attack is possible with CVE-2024-10903?
CVE-2024-10903 allows for server-side request forgery (SSRF) attacks due to insufficient validation of link URLs.
What does CVE-2024-10903 affect?
CVE-2024-10903 affects the Broken Link Checker plugin for WordPress, specifically versions earlier than 2.4.2.