๐Ÿ” CVE Alert

CVE-2026-97316

UNKNOWN 0.0

Broken Link Notifier 1.3.1 - 2.0.0 - Unauthenticated SSRF via Redirect Bypass

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Broken Link Notifier WordPress plugin before 2.0.0.1 does not re-validate the destination of redirects when checking links, allowing unauthenticated attackers to bypass its internal-address filter and make the server send requests to internal services.

Vendor unknown
Product broken link notifier
Published Sep 30, 2026
Stay Ahead of the Next One

Get instant alerts for unknown broken link notifier

Be the first to know when new unknown vulnerabilities affecting unknown broken link notifier are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Broken Link Notifier
1.3.1 < 2.0.0.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/d9497ddd-c39c-4928-8660-f1c94ef2c3a0/

Credits

Amin Guliyev WPScan