CVE-2025-4047: Broken Link Checker <= 2.4.4 - Missing Autorization to Authenticated (Subscriber+) Plugin Status Dashboard View
The Broken Link Checker plugin for WordPress is vulnerable to unauthorized data access due to a missing capability check on the ajaxfullstatus and ajaxdashboardstatus functions in all versions up to, and including, 2.4.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view the plugin's status.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4047?
CVE-2025-4047 is considered a moderate severity vulnerability due to the potential for unauthorized data access.
How do I fix CVE-2025-4047?
To fix CVE-2025-4047, update the Broken Link Checker plugin to the latest version beyond 2.4.4.
Who is affected by CVE-2025-4047?
CVE-2025-4047 affects all versions of the Broken Link Checker plugin for WordPress up to and including version 2.4.4.
What functions are vulnerable in CVE-2025-4047?
CVE-2025-4047 primarily affects the ajax_full_status and ajax_dashboard_status functions due to a missing capability check.
Can unauthenticated users exploit CVE-2025-4047?
No, CVE-2025-4047 requires authenticated attackers to exploit the vulnerability, but it still poses a significant risk.