WordPress Plugin Vulnerabilities
Broken Link Checker <= 1.10.2 - Stored XSS
Description
Broken Link Checker is vulnerable to stored XSS (again). The plugin don’t check the links on their validity. Very bad: JavaScript code is a valid link. Example: <a href="javascript:alert(1)">Link</a>.
Malicious JavaScript can be injected by any post author.
Screenshots: http://imgur.com/mTEobu7 / http://imgur.com/3z8GmL0 / http://imgur.com/KLSTP3S
Affects Plugins
Classification
Type
XSS
OWASP top 10
CWE
Miscellaneous
Submitter
SecuBeastTeam
Verified
No
WPVDB ID
Timeline
Publicly Published
2014-12-05 (about 11 years ago)
Added
2019-12-02 (about 6 years ago)
Last Updated
2019-12-02 (about 6 years ago)