Extension WordPress
Vulnérabilités Broken Link Checker
Cette page rassemble les failles publiées pour Broken Link Checker, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Broken Link Checker
12 fiches
Broken Link Checker <= 2.4.7 – Authenticated (Editor+) SQL Injection
The Broken Link Checker plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.4.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.…
*-2.4.7
2.4.8
26/03/2026
Broken Link Checker <= 2.4.4 – Missing Autorization to Authenticated (Subscriber+) Plugin Status Dashboard View
The Broken Link Checker plugin for WordPress is vulnerable to unauthorized data access due to a missing capability check on the ajax_full_status and ajax_dashboard_status functions in all versions up to, and including, 2.4.4. This makes it possible for…
*-2.4.4
2.4.5
02/06/2025
Broken Link Checker <= 2.4.1 – Authenticated (Admin+) Server-Side Request Forgery
The Broken Link Checker plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.4.1. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to…
*-2.4.1
2.4.2
05/12/2024
Broken Link Checker <= 2.4.0 – Reflected Cross-Site Scripting
The Broken Link Checker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg in /app/admin-notices/features/class-view.php without appropriate escaping on the URL in all versions up to, and including, 2.4.0. This makes it…
*-2.4.0
2.4.1
30/09/2024
Broken Link Checker <= 2.2.3 – Authenticated (Administrator+) Stored Cross-Site Scripting via settings
The Broken Link Checker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.2.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
*-2.2.3
2.2.4
12/02/2024
Broken Link Checker <= 1.11.19 – Authenticated (Administrator+) Stored Cross-Site Scripting
The Broken Link Checker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘youtube_api_key’ parameter in versions up to, and including, 1.11.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
*-1.11.19
1.11.20
11/11/2022
Broken Link Checker <= 1.11.16 – Authenticated (Admin+) PHAR Deserialization
The Broken Link Checker plugin for WordPress is vulnerable to deserialization of untrusted input via the '$log_file' value in versions up to, and including 1.11.16. This makes it possible for authenticated attackers with administrative privileges and above to…
*-1.11.16
1.11.17
18/07/2022
Broken Link Checker <= 1.11.8 – Reflected Cross-Site Scripting
The Broken Link Checker plugin through 1.11.8 for WordPress is susceptible to Reflected XSS due to improper encoding and insertion of an HTTP GET parameter into HTML. The filter function on the page listing all detected broken links…
[*, 1.11.9)
1.11.9
15/10/2019
Broken Link Checker <= 1.11.8 – Reflected Cross-Site Scripting
A reflected XSS vulnerability was found in includes/admin/table-printer.php in the Broken Link Checker plugin 1.11.8 for WordPress. This allows unauthorized users to inject client-side JavaScript into an admin-only WordPress page via the wp-admin/tools.php?page=view-broken-links s_filter parameter in a search…
[*, 1.11.9)
1.11.9
14/10/2019
Broken Link Checker <= 1.10.8 – Cross-Site Scripting
Cross-site scripting (XSS) vulnerability exists in the Wordpress admin panel when the Broken Link Checker plugin before 1.10.9 is installed.
[*, 1.10.9)
1.10.9
29/06/2015
Broken Link Checker < 1.10.6 – Reflected Cross Site Scripting
The Broken Link Checker plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.10.5 due to insufficient input sanitization and output escaping and the use of add_query_arg/remove_query_arg. This makes it possible for attackers…
[*, 1.10.6)
1.10.6
20/04/2015
Broken Link Checker < 1.10.2 – Authenticated (Admin+) Stored Cross-Site Scripting
The Broken Link Checker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘exclusion_list’ parameter in versions up to, and including, 1.10.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
[*, 1.10.2)
1.10.2
05/12/2014
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.