CVE-2025-6851: Broken Link Notifier <= 1.3.0 - Unauthenticated Server-Side Request Forgery
The Broken Link Notifier plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.3.0 via the ajaxblinks() function which ultimately calls the checkurlstatuscode() function. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Broken Link Notifier pluginto a version that resolves this vulnerability.Fixed in 1.3.0 - Compensating control
Restrict access to the WordPress application so only trusted/authorized users can reach the Broken Link Notifier functionality (mitigate unauthenticated SSRF exploitation).
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6851?
CVE-2025-6851 is considered a critical vulnerability due to its potential for Server-Side Request Forgery, allowing unauthenticated attackers to exploit the flaw.
How do I fix CVE-2025-6851?
To mitigate CVE-2025-6851, upgrade the Broken Link Notifier plugin to the latest version beyond 1.3.0.
Who is affected by CVE-2025-6851?
CVE-2025-6851 affects all versions of the Broken Link Notifier plugin for WordPress up to and including version 1.3.0.
What type of attack is CVE-2025-6851 associated with?
CVE-2025-6851 is associated with Server-Side Request Forgery attacks.
Can CVE-2025-6851 be exploited remotely?
Yes, CVE-2025-6851 can be exploited remotely by unauthenticated attackers.