{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3abroken_link_checker_projectbroken_link_checkerwordpress/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:broken_link_checker_project:broken_link_checker:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-75528"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Broken Link Checker (\u003c= 2.4.13)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe Broken Link Checker plugin for WordPress, in versions up to and including 2.4.13, contains a security flaw resulting in Stored Cross-Site Scripting (XSS). The vulnerability stems from insufficient input sanitization and output escaping within the plugin's Comment Author URL and Link Log processing functions. An unauthenticated attacker can craft a malicious URL and submit it as a comment author link. When an administrator performs the plugin's standard \u0026quot;dismiss-and-recheck\u0026quot; workflow, the plugin fetches the malicious URL. The attacker's server then issues a redirect to a secondary URL containing an HTML/JavaScript payload. This payload is stored verbatim in the plugin's link log, where it executes upon being rendered in an administrative session. This vulnerability poses a significant risk to the integrity of the WordPress administrative environment.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-75528 allows an unauthenticated attacker to execute arbitrary JavaScript in the context of an administrator's browser session. This could lead to account takeover, unauthorized administrative actions, or the injection of further malicious content into the site, impacting any WordPress installation using the vulnerable plugin version.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eUpdate the Broken Link Checker plugin to the latest version, ensuring it exceeds 2.4.13. Security operations should review administrative access logs for unusual patterns involving the \u0026quot;dismiss-and-recheck\u0026quot; functionality and monitor web application firewall (WAF) logs for POST requests to WordPress comment submission endpoints containing non-standard URL schemes or script-like patterns.\u003c/p\u003e\n","date_modified":"2026-09-02T09:12:31Z","date_published":"2026-09-02T09:12:31Z","id":"https://feed.craftedsignal.io/briefs/2026-09-broken-link-checker-xss/","summary":"The Broken Link Checker WordPress plugin up to version 2.4.13 is vulnerable to Stored Cross-Site Scripting, allowing unauthenticated attackers to execute malicious scripts in the administrative session context.","title":"CVE-2026-75528 Stored XSS in Broken Link Checker WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-broken-link-checker-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:broken_link_checker_project:broken_link_checker:*:*:*:*:*:wordpress:*:*","version":"https://jsonfeed.org/version/1.1"}