Broken Link Notifier WordPress Plugin CSV Injection Vulnerability
Vulnerability
A CSV injection vulnerability has been identified in the Broken Link Notifier plugin for WordPress, affecting all versions through 1.3.0. The vulnerability allows authenticated attackers with Contributor-level access and above to inject untrusted data into exported CSV files. When these files are downloaded and opened in a local environment with a vulnerable configuration, it could lead to code execution.
Impact
Exploitation of this vulnerability could result in arbitrary code execution on a local system where the exported CSV file is opened, given that the system is configured in a way that allows such execution.
Remediation
Users are advised to update the Broken Link Notifier plugin to version 1.3.1 or a newer patched version.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
