Broken Link Notifier WordPress Plugin CSV Injection Vulnerability

Vulnerability

A CSV injection vulnerability has been identified in the Broken Link Notifier plugin for WordPress, affecting all versions through 1.3.0. The vulnerability allows authenticated attackers with Contributor-level access and above to inject untrusted data into exported CSV files. When these files are downloaded and opened in a local environment with a vulnerable configuration, it could lead to code execution.

Impact

Exploitation of this vulnerability could result in arbitrary code execution on a local system where the exported CSV file is opened, given that the system is configured in a way that allows such execution.

Remediation

Users are advised to update the Broken Link Notifier plugin to version 1.3.1 or a newer patched version.

Added: Jul 11, 2025, 9:18 AM
Updated: Jul 11, 2025, 9:18 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
5.7
remediation
7.7
relevance
0.2
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.