nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-12121 CVE-2024-12121
MEDIUM
Broken Link Checker | Finder <= 2.5.0 - Authenticated (Author+) Blind Server-Side Request Forgery
Record summary
CVE-2024-12121 has a selected CVSS score of 5.4 (medium).
Description
The Broken Link Checker | Finder plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 2.5.0 via the 'moblc_check_link' function. This makes it possible for authenticated attackers, with Author-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 20, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Broken Link Checker | FinderBrowse cyberlord92 / Broken Link Checker | FinderDefault status: unaffected | CVE List | Through 2.5.0 | affected |
References
3plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/changeset/3207590/broken-link-finder wordfence.com
https://www.wordfence.com/threat-intel/vulnerabilities/id/fa52034e-3d11-4be5-ab8b-8f7256be2a3e?source=cve