CVE-2026-97316: Broken Link Notifier 1.3.1 - 2.0.0 - Unauthenticated SSRF via Redirect Bypass
Published Sep 30, 2026
·Updated
The Broken Link Notifier WordPress plugin before 2.0.0.1 does not re-validate the destination of redirects when checking links, allowing unauthenticated attackers to bypass its internal-address filter and make the server send requests to internal services.
Affected Software
1 affected component
Broken Link Notifier Broken Link Notifier<2.0.0.1
Event History
Sep 30, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:17 AM
Description
Frequently Asked Questions
1
Which deployments are affected?
Broken Link Notifier versions before 2.0.0.1 are affected. The issue occurs when the plugin checks links and follows redirects.
2
Does exploitation require authentication?
No. An unauthenticated attacker can exploit the redirect handling to cause the server to send requests to internal services.
3
What is the practical impact of the redirect bypass?
The plugin's internal-address filter can be bypassed if a checked link redirects to an internal destination. This enables server-side requests to internal services that the filter was intended to block.