CVE-2026-97316 PUBLISHED

Broken Link Notifier 1.3.1 - 2.0.0 - Unauthenticated SSRF via Redirect Bypass

Assigner: WPScan
Reserved: 24.09.2026 Published: 30.09.2026 Updated: 30.09.2026

The Broken Link Notifier WordPress plugin before 2.0.0.1 does not re-validate the destination of redirects when checking links, allowing unauthenticated attackers to bypass its internal-address filter and make the server send requests to internal services.

Product Status

Vendor Unknown
Product Broken Link Notifier
Versions Default: unaffected
  • affected from 1.3.1 to 2.0.0.1 (excl.)

Credits

  • Amin Guliyev finder
  • WPScan coordinator

References

Problem Types

  • CWE-918 Server-Side Request Forgery (SSRF) CWE