Vulnerabilidades conocidas, compatibilidad con PHP y alternativas más seguras para el plugin de WordPress Broken Link Checker — verificado contra la base de datos de seguridad local de WP Clinic.
Qué hace este plugin
- Slug:
broken-link-checker
- 500000+ instalaciones activas
broken imagesbroken linksexternal linkinternal linklinks
Estado de mantenimiento
- Última versión conocida: 2.4.8
- Requiere PHP: 7.4+
- PHP máximo soportado (analizado): 8.4
Vulnerabilidades conocidas
12 CVEs conocidos registrados para Broken Link Checker.
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
CVE-2026-39466
|
Broken Link Checker [broken-link-checker] < 2.4.8 |
— |
Alta
7,6
|
< 2.4.8
|
2.4.8 |
2026-03-26 |
✓ corregido en la última versión
|
|
CVE-2024-10903
|
Broken Link Checker [broken-link-checker] < 2.4.2 |
Falsificación de petición del lado del servidor (SSRF) |
Media
4,7
|
< 2.4.2
|
2.4.2 |
2024-12-05 |
✓ corregido en la última versión
|
|
CVE-2024-8981
|
Broken Link Checker [broken-link-checker] < 2.4.1 |
Neutralización incorrecta de etiquetas HTML relacionadas con scripts en una página web (XSS básico) |
Alta
7,1
|
< 2.4.1
|
2.4.1 |
2024-09-30 |
✓ corregido en la última versión
|
|
CVE-2024-25592
|
Broken Link Checker [broken-link-checker] < 2.2.4 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,9
|
< 2.2.4
|
2.2.4 |
2024-02-12 |
✓ corregido en la última versión
|
|
—
|
Broken Link Checker [broken-link-checker] < 1.10.2 |
— |
Desconocido
|
< 1.10.2
|
1.10.2 |
2023-12-04 |
✓ corregido en la última versión
|
|
—
|
Broken Link Checker [broken-link-checker] < 1.9.2 |
— |
Desconocido
|
< 1.9.2
|
1.9.2 |
2023-08-01 |
✓ corregido en la última versión
|
|
CVE-2014-125105
|
Broken Link Checker [broken-link-checker] < 1.10.2 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,1
|
< 1.10.2
|
1.10.2 |
2023-06-05 |
✓ corregido en la última versión
|
|
—
|
Broken Link Checker [broken-link-checker] < 1.10.6 |
— |
Desconocido
|
< 1.10.6
|
1.10.6 |
2023-04-20 |
✓ corregido en la última versión
|
CVE-2026-39466
The Broken Link Checker plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.4.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with editor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2024-10903
The Broken Link Checker plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.4.1. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to arbitrary locations originating from the web application which can be used to query and modify information from internal services.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2024-8981
The Broken Link Checker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg in /app/admin-notices/features/class-view.php without appropriate escaping on the URL in all versions up to, and including, 2.4.0. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-25592
Update the WordPress Broken Link Checker plugin to the latest available version (at least 2.2.4).
Dhabaleshwar Das discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Broken Link Checker Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 2.2.4.
This vulnerability was reported to and published by Patchstack. Our users receive alerts and protections up to 48 hours in advance.
Have additional information or questions about this entry? Get in touch.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Broken Link Checker [broken-link-checker] < 1.10.2
Update the plugin.
An unknown person discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Broken Link Checker Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 1.10.2.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Broken Link Checker [broken-link-checker] < 1.9.2
Update the plugin.
An unknown person discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Broken Link Checker Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 1.9.2.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2014-125105
A vulnerability was found in Broken Link Checker Plugin up to 1.10.1 on WordPress. It has been declared as problematic. Affected by this vulnerability is the function options_page of the file core/core.php of the component Settings Page. The manipulation of the argument exclusion_list/blc_custom_fields leads to cross site scripting. The attack can be launched remotely. Upgrading to version 1.10.2 is able to address this issue. The patch is named 90615fe9b0b6f9e6fb254d503c302e53a202e561. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-230659.
[de] In Broken Link Checker Plugin bis 1.10.1 für WordPress wurde eine problematische Schwachstelle ausgemacht. Hierbei betrifft es die Funktion options_page der Datei core/core.php der Komponente Settings Page. Dank der Manipulation des Arguments exclusion_list/blc_custom_fields mit unbekannten Daten kann eine cross site scripting-Schwachstelle ausgenutzt werden. Umgesetzt werden kann der Angriff über das Netzwerk. Ein Aktualisieren auf die Version 1.10.2 vermag dieses Problem zu lösen. Der Patch wird als 90615fe9b0b6f9e6fb254d503c302e53a202e561 bezeichnet. Als bestmögliche Massnahme wird das Einspielen eines Upgrades empfohlen.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
Broken Link Checker [broken-link-checker] < 1.10.6
Update the plugin.
An unknown person discovered and reported this Multiple Vulnerabilities vulnerability in WordPress Broken Link Checker Plugin. Multiple vulnerabilities were found. Due to the large number of vulnerabilities, this has been grouped in this category. This vulnerability has been fixed in version 1.10.6.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
+ 15 vulnerabilidades conocidas más
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
CVE-2015-10098
|
Broken Link Checker [broken-link-checker] < 1.10.6 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,1
|
< 1.10.6
|
1.10.6 |
2023-04-08 |
✓ corregido en la última versión
|
|
CVE-2022-3922
|
Broken Link Checker [broken-link-checker] < 1.11.20 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
4,8
|
< 1.11.20
|
1.11.20 |
2022-11-11 |
✓ corregido en la última versión
|
|
CVE-2022-2438
|
Broken Link Checker [broken-link-checker] < 1.11.17 |
Deserialización de datos no confiables |
Alta
7,2
|
< 1.11.17
|
1.11.17 |
2022-07-18 |
✓ corregido en la última versión
|
|
CVE-2019-16521
|
Broken Link Checker [broken-link-checker] < 1.11.9 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,1
|
< 1.11.9
|
1.11.9 |
2019-10-15 |
✓ corregido en la última versión
|
|
CVE-2019-17207
|
Broken Link Checker [broken-link-checker] < 1.11.9 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 1.11.9
|
1.11.9 |
2019-10-14 |
✓ corregido en la última versión
|
|
CVE-2015-5057
|
Broken Link Checker [broken-link-checker] < 1.10.9 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,1
|
< 1.10.9
|
1.10.9 |
2015-06-29 |
✓ corregido en la última versión
|
|
—
|
Broken Link Checker [broken-link-checker] < 1.10.6 |
— |
Desconocido
|
< 1.10.6
|
1.10.6 |
2015-04-20 |
✓ corregido en la última versión
|
|
—
|
Broken Link Checker [broken-link-checker] < 1.10.6 |
— |
Desconocido
|
< 1.10.6
|
1.10.6 |
2015-04-20 |
✓ corregido en la última versión
|
|
—
|
Broken Link Checker [broken-link-checker] < 1.10.2 |
— |
Desconocido
|
< 1.10.2
|
1.10.2 |
2014-12-05 |
✓ corregido en la última versión
|
|
—
|
Broken Link Checker [broken-link-checker] < 1.10.2 |
— |
Desconocido
|
< 1.10.2
|
1.10.2 |
2014-12-04 |
✓ corregido en la última versión
|
|
—
|
Broken Link Checker [broken-link-checker] < 1.9.2 |
— |
Desconocido
|
< 1.9.2
|
1.9.2 |
2014-08-01 |
✓ corregido en la última versión
|
|
CVE-2025-4047
|
Broken Link Checker [broken-link-checker] < 2.4.5 |
Falta de control de autorización |
Media
4,3
|
< 2.4.5
|
2.4.5 |
0000-00-00 |
✓ corregido en la última versión
|
|
—
|
Broken Link Checker [broken-link-checker] < 1.10.6 |
— |
Desconocido
|
< 1.10.6
|
1.10.6 |
— |
✓ corregido en la última versión
|
|
—
|
Broken Link Checker [broken-link-checker] < 1.10.3 |
— |
Desconocido
|
< 1.10.3
|
1.10.3 |
— |
✓ corregido en la última versión
|
|
—
|
Broken Link Checker [broken-link-checker] < 1.10.2 |
— |
Desconocido
|
< 1.10.2
|
1.10.2 |
— |
✓ corregido en la última versión
|
CVE-2015-10098
A vulnerability was found in Broken Link Checker Plugin up to 1.10.5 on WordPress. It has been rated as problematic. Affected by this issue is the function print_module_list/show_warnings_section_notice/status_text/ui_get_action_links. The manipulation leads to cross site scripting. The attack may be launched remotely. Upgrading to version 1.10.6 is able to address this issue. The name of the patch is f30638869e281461b87548e40b517738b4350e47. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-225152.
[de] Eine problematische Schwachstelle wurde in Broken Link Checker Plugin bis 1.10.5 für WordPress ausgemacht. Dies betrifft die Funktion print_module_list/show_warnings_section_notice/status_text/ui_get_action_links. Durch Manipulation mit unbekannten Daten kann eine cross site scripting-Schwachstelle ausgenutzt werden. Der Angriff kann über das Netzwerk passieren. Ein Aktualisieren auf die Version 1.10.6 vermag dieses Problem zu lösen. Der Patch wird als f30638869e281461b87548e40b517738b4350e47 bezeichnet. Als bestmögliche Massnahme wird das Einspielen eines Upgrades empfohlen.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2022-3922
The Broken Link Checker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘youtube_api_key’ parameter in versions up to, and including, 1.11.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2022-2438
The Broken Link Checker plugin for WordPress is vulnerable to deserialization of untrusted input via the '$log_file' value in versions up to, and including 1.11.16. This makes it possible for authenticated attackers with administrative privileges and above to call files using a PHAR wrapper that will deserialize the data and call arbitrary PHP Objects that can be used to perform a variety of malicious actions granted a POP chain is also present. It also requires that the attacker is successful in uploading a file with the serialized payload.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2019-16521
The broken-link-checker plugin through 1.11.8 for WordPress (aka Broken Link Checker) is susceptible to Reflected XSS due to improper encoding and insertion of an HTTP GET parameter into HTML. The filter function on the page listing all detected broken links can be exploited by providing an XSS payload in the s_filter GET parameter in a filter_id=search request. NOTE: this is an end-of-life product.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2019-17207
A reflected XSS vulnerability was found in includes/admin/table-printer.php in the broken-link-checker (aka Broken Link Checker) plugin 1.11.8 for WordPress. This allows unauthorized users to inject client-side JavaScript into an admin-only WordPress page via the wp-admin/tools.php?page=view-broken-links s_filter parameter in a search action.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2015-5057
Cross-site scripting (XSS) vulnerability exists in the Wordpress admin panel when the Broken Link Checker plugin before 1.10.9 is installed.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
Broken Link Checker [broken-link-checker] < 1.10.6
This plugin is prone to a cross site scripting and cross site request forgery vulnerability.
Update the plugin.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Broken Link Checker [broken-link-checker] < 1.10.6
The Broken Link Checker plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.10.5 due to insufficient input sanitization and output escaping and the use of add_query_arg/remove_query_arg. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Broken Link Checker [broken-link-checker] < 1.10.2
The Broken Link Checker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘exclusion_list’ parameter in versions up to, and including, 1.10.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Broken Link Checker [broken-link-checker] < 1.10.2
Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.
Update the plugin.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Broken Link Checker [broken-link-checker] < 1.9.2
This plugin is prone to a cross site scripting vulnerability.
Update the plugin.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2025-4047
The Broken Link Checker plugin for WordPress is vulnerable to unauthorized data access due to a missing capability check on the ajax_full_status and ajax_dashboard_status functions in all versions up to, and including, 2.4.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view the plugin's status.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Broken Link Checker [broken-link-checker] < 1.10.6
The Broken Link Checker WordPress plugin was affected by a CSRF/XSS security vulnerability.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
Broken Link Checker [broken-link-checker] < 1.10.3
Broken Link Checker is vulnerable to stored XSS (again). The plugin don’t check the links on their validity. Very bad: JavaScript code is a valid link. Example: <a href="javascript:alert(1)">Link</a>.
Malicious JavaScript can be injected by any post author.
Screenshots: http://imgur.com/mTEobu7 / http://imgur.com/3z8GmL0 / http://imgur.com/KLSTP3S
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
Cómo solucionarlo
Mantén Broken Link Checker actualizado — 2.4.8 es la última versión en wordpress.org, y cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en").
Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.
Alternativas más seguras / más establecidas