CVE-2015-10098
Broken Link Checker < 1.10.6 - Reflected Cross Site Scripting
mediumImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
5.3
CVSS Score
5.3
CVSS Score
medium
Severity
1.10.6
Patched in
3216d
Time to patch
Description
The Broken Link Checker plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.10.5 due to insufficient input sanitization and output escaping and the use of add_query_arg/remove_query_arg. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
CVSS Vector Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NAttack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
None
Confidentiality
Low
Integrity
None
Availability
Technical Details
Affected versions
<1.10.6PublishedApril 20, 2015
Last updatedFebruary 7, 2024
Affected pluginbroken-link-checker
Check if your site is affected.
Run a free security audit to detect vulnerable plugins, outdated versions, and misconfigurations.