Skip to main content
Vulnerability Database/CVE-2026-97316

CVE-2026-97316: Broken Link Notifier SSRF Vulnerability

CVE-2026-97316 is a server-side request forgery flaw in Broken Link Notifier WordPress plugin that lets unauthenticated attackers bypass filters to access internal services. This article covers technical details, affected versions, impact, and mitigation steps.

Published:

CVE-2026-97316 Overview

CVE-2026-97316 is a Server-Side Request Forgery (SSRF) vulnerability in the Broken Link Notifier WordPress plugin in versions prior to 2.0.0.1. The plugin fails to re-validate redirect destinations during its link-checking routine. Unauthenticated attackers can bypass the internal-address filter by hosting a URL that redirects to internal services. The WordPress server then issues requests to those internal endpoints on the attacker's behalf. This exposes internal infrastructure, cloud metadata endpoints, and unauthenticated internal APIs to remote probing.

Critical Impact

Unauthenticated attackers can coerce vulnerable WordPress installations into issuing HTTP requests to internal network services, bypassing perimeter controls.

Affected Products

  • Broken Link Notifier WordPress plugin versions prior to 2.0.0.1
  • WordPress installations with the plugin enabled and reachable link-checking endpoints
  • Environments where the WordPress host has network access to internal services or cloud metadata endpoints

Discovery Timeline

  • 2026-09-30 - CVE CVE-2026-97316 published to NVD
  • 2026-09-30 - Last updated in NVD database

Technical Details for CVE-2026-97316

Vulnerability Analysis

The Broken Link Notifier plugin validates URLs against an internal-address filter before issuing HTTP requests to check link status. The filter blocks direct requests to private IP ranges and localhost. However, the plugin follows HTTP redirects returned by remote servers without re-applying the filter to the redirect target. An attacker registers an external URL that returns an HTTP 301 or 302 response pointing to an internal address such as http://127.0.0.1, http://169.254.169.254, or an internal service IP. The plugin passes the initial URL validation, then follows the redirect and sends the request to the internal target.

This SSRF condition [CWE-918] allows attackers to reach services that are otherwise unreachable from the internet. Common targets include cloud provider metadata endpoints, internal admin panels, databases exposed on loopback, and Kubernetes API servers.

Root Cause

The root cause is missing re-validation of the destination host after HTTP redirects. The plugin applies its allowlist or denylist only to the user-supplied URL, not to each hop in the redirect chain. Follow-redirect behavior is enabled in the underlying HTTP client without a per-hop hook to re-check the resolved address.

Attack Vector

The attack requires no authentication. An attacker submits a link to the plugin's checking mechanism, or waits for the plugin to check a link the attacker has planted in a comment or content field. The attacker-controlled server returns a redirect to an internal target. The WordPress server issues the request and, depending on the plugin's response handling, may return status codes, response sizes, or content excerpts observable by the attacker.

Technical details are available in the WPScan Vulnerability Report.

Detection Methods for CVE-2026-97316

Indicators of Compromise

  • Outbound HTTP requests from the WordPress host to 169.254.169.254, 127.0.0.1, or RFC1918 addresses originating from PHP processes
  • Access log entries showing the plugin's link-checking endpoint being invoked with external URLs that resolve via redirect to internal hosts
  • Unexpected requests in internal service logs sourced from the WordPress server's IP

Detection Strategies

  • Monitor egress traffic from WordPress hosts and alert on connections to cloud metadata IPs or private ranges
  • Inspect web server logs for repeated requests to the Broken Link Notifier plugin endpoints from unauthenticated sessions
  • Correlate outbound HTTP requests with PHP-FPM worker process ancestry to identify SSRF activity

Monitoring Recommendations

  • Enable verbose logging on the WordPress reverse proxy to capture full redirect chains handled by plugins
  • Alert on any process on the WordPress host attempting to reach 169.254.169.254 or IMDSv1 endpoints
  • Track plugin version inventory across WordPress fleets to identify installations below 2.0.0.1

How to Mitigate CVE-2026-97316

Immediate Actions Required

  • Upgrade the Broken Link Notifier plugin to version 2.0.0.1 or later on all WordPress installations
  • Disable the plugin until the update is applied if patching cannot occur immediately
  • Enforce IMDSv2 on AWS EC2 instances hosting WordPress to prevent metadata credential theft via SSRF

Patch Information

The vendor released version 2.0.0.1 which re-validates redirect destinations against the internal-address filter on every hop. Update through the WordPress plugin dashboard or via WP-CLI using wp plugin update broken-link-notifier. Refer to the WPScan Vulnerability Report for release confirmation.

Workarounds

  • Restrict outbound network access from WordPress hosts to only required external endpoints using an egress firewall or proxy allowlist
  • Block WordPress host access to cloud metadata endpoints and internal management networks at the network layer
  • Deploy a Web Application Firewall rule to rate-limit or block anonymous requests to the plugin's link-checking endpoints
bash
# Example egress restriction using iptables to block metadata endpoint access
iptables -A OUTPUT -d 169.254.169.254 -j DROP
iptables -A OUTPUT -d 127.0.0.0/8 ! -o lo -j DROP
iptables -A OUTPUT -d 10.0.0.0/8 -p tcp --dport 80 -j DROP
iptables -A OUTPUT -d 192.168.0.0/16 -p tcp --dport 80 -j DROP

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.