CVE-2024-12121: Broken Link Checker | Finder <= 2.5.0 - Authenticated (Author+) Blind Server-Side Request Forgery
The Broken Link Checker | Finder plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 2.5.0 via the 'moblcchecklink' function. This makes it possible for authenticated attackers, with Author-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12121?
CVE-2024-12121 is classified as a medium severity vulnerability due to its potential for exploitation by authenticated attackers.
How do I fix CVE-2024-12121?
To mitigate CVE-2024-12121, update the Broken Link Checker Finder plugin to version 2.5.1 or later.
Who is affected by CVE-2024-12121?
CVE-2024-12121 affects all users of the Broken Link Checker Finder plugin for WordPress with versions up to and including 2.5.0.
What type of vulnerability is CVE-2024-12121?
CVE-2024-12121 is a Blind Server-Side Request Forgery vulnerability.
What capabilities do attackers gain from CVE-2024-12121?
Authenticated attackers with Author-level access and above can exploit CVE-2024-12121 to make unauthorized requests to internal services.