CVE · High

CVE-2022-2438 — Broken Link Checker [broken-link-checker] < 1.11.17

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-2438 Broken Link Checker [broken-link-checker] < 1.11.17 Deserialization of Untrusted Data High 7.2 < 1.11.17 1.11.17 2022-07-18

CVE-2022-2438

The Broken Link Checker plugin through version 1.11.16 allows authenticated administrators to exploit unsafe deserialization through the log_file parameter, potentially enabling execution of arbitrary PHP code if a PHAR wrapper is used in conjunction with an uploaded file containing a malicious serialized payload and a suitable gadget chain exists. This vulnerability requires both administrative access and successful file upload capability to be exploited.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.