CVE-2024-10903
Last modified
CVE-2024-10903 is a medium-severity vulnerability rated 4.7/10 on the CVSS scale. The Broken Link Checker WordPress plugin before 2.4.2 does not validate a the link URLs before making a request to them, which could allow admin users to perform SSRF attack, for example on a multisite installation.. EPSS estimates a 0.34% chance of exploitation in the next 30 days.
Description
The Broken Link Checker WordPress plugin before 2.4.2 does not validate a the link URLs before making a request to them, which could allow admin users to perform SSRF attack, for example on a multisite installation.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Managewp | Broken Link Checker | < 2.4.2 |
References
- https://wpscan.com/vulnerability/39027390-ce01-4dd5-a979-426785aa7acb/Exploit, Third Party Advisory
- https://wpscan.com/vulnerability/39027390-ce01-4dd5-a979-426785aa7acb/Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-10903?
How severe is CVE-2024-10903?
How do I fix CVE-2024-10903?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-10898The Contact Form 7 Email Add on plugin for WordPress is vuln…8.8
- CVE-2024-10899The The WooCommerce Product Table Lite plugin for WordPress …7.3
- CVE-2024-1090The ImageRecycle pdf & image compression plugin for WordPres…4.3
- CVE-2024-10900The ProfileGrid – User Profiles, Groups and Communities plug…8.1
- CVE-2024-10901In eosphoros-ai/db-gpt version v0.6.0, the web API `POST /ap…9.8
- CVE-2024-10902In eosphoros-ai/db-gpt version v0.6.0, the web API `POST /v1…9.8
- CVE-2024-10904There is a stored Cross-site Scripting vulnerability in ArcG…4.8
- CVE-2024-10905IdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p2, Iden…9.8
- CVE-2024-10906In version 0.6.0 of eosphoros-ai/db-gpt, the `uvicorn` app c…8.1
- CVE-2024-10907In lm-sys/fastchat Release v0.2.36, the server fails to hand…7.5
- CVE-2024-10908An open redirect vulnerability in lm-sys/fastchat Release v0…6.1
- CVE-2024-10909The The Pojo Forms plugin for WordPress is vulnerable to arb…6.3
Are you affected by CVE-2024-10903?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
