WordPress Plugin Vulnerabilities

Broken Link Checker <= 1.10.2 - Stored XSS

Description

Broken Link Checker is vulnerable to stored XSS (again). The plugin don’t check the links on their validity. Very bad: JavaScript code is a valid link. Example: <a href="javascript:alert(1)">Link</a>.
Malicious JavaScript can be injected by any post author.

Screenshots: http://imgur.com/mTEobu7 / http://imgur.com/3z8GmL0 / http://imgur.com/KLSTP3S

Affects Plugins

Fixed in 1.10.3

Classification

Type
XSS
CWE

Miscellaneous

Submitter
SecuBeastTeam
Verified
No

Timeline

Publicly Published
2014-12-05 (about 11 years ago)
Added
2019-12-02 (about 6 years ago)
Last Updated
2019-12-02 (about 6 years ago)

Other