DIRAS TAKE
Urgent: this is a stored XSS that can be injected without login and there is no patch available for 2.4.13 and earlier, so immediately limit administrative exposure and avoid the plugin workflow that processes untrusted links.
What is CVE-2026-75528?
Unauthenticated attackers can store and later execute arbitrary web scripts in the Broken Link Checker WordPress plugin, enabling script execution in pages viewed by administrators or other users. CVE-2026-75528 affects Broken Link Checker 2.x, specifically version 2.4.13 and earlier. The issue arises when an attacker supplies a crafted comment author URL that is stored in the plugin's link log and later triggered after an administrator performs the plugin’s dismiss-and-recheck workflow. The weakness is classified as CWE-79 (Cross-site Scripting).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Which versions of wpmudev Broken Link Checker are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 2.x | 2.4.13 and earlier |
Is CVE-2026-75528 being exploited?
There are no public reports of exploitation as of 2026-09-30.
How to fix CVE-2026-75528
- Deactivate the Broken Link Checker plugin until a vendor patch is available.
- Restrict administrative access to WordPress and the plugin UI to trusted IPs or VPNs.
- Avoid performing the plugin’s dismiss-and-recheck workflow on links from untrusted commenters.
- Monitor logs for suspicious redirects or unexpected link entries and apply vendor guidance when published.
Frequently asked questions
Is CVE-2026-75528 being actively exploited?
There are no public reports of active exploitation of CVE-2026-75528 as of 2026-09-30.
Which Broken Link Checker versions are affected by CVE-2026-75528?
Broken Link Checker 2.x is affected; specifically version 2.4.13 and earlier are listed as vulnerable.
Is there a patch for CVE-2026-75528?
No patch is listed for Broken Link Checker as of 2026-09-30; follow vendor guidance and apply mitigations until a fixed release is available.
Does CVE-2026-75528 require authentication?
The vulnerability allows unauthenticated attackers to inject payloads, though exploitation depends on an administrator later triggering the plugin’s dismiss-and-recheck workflow.
References
- nvd.nist.gov/vuln/detail/CVE-2026-75528
- cve.org/CVERecord?id=CVE-2026-75528
- wordfence.com/threat-intel/vulnerabilities/id/ec96308f-3944-48c5-94be-b1555c0830b7?source=cve
- plugins.trac.wordpress.org/browser/broken-link-checker/tags/2.4.13/legacy/includes/admin/table-printer.php#L658
- plugins.trac.wordpress.org/browser/broken-link-checker/tags/2.4.13/legacy/includes/links.php#L485
- plugins.trac.wordpress.org/browser/broken-link-checker/tags/2.4.13/legacy/modules/checkers/http.php#L291
- plugins.trac.wordpress.org/browser/broken-link-checker/tags/2.4.13/legacy/modules/checkers/http.php#L432
- plugins.trac.wordpress.org/browser/broken-link-checker/tags/2.4.13/legacy/modules/containers/comment.php#L228
- plugins.trac.wordpress.org/browser/broken-link-checker/tags/2.4.8/legacy/includes/admin/table-printer.php#L658
- plugins.trac.wordpress.org/browser/broken-link-checker/tags/2.4.8/legacy/includes/links.php#L485
- plugins.trac.wordpress.org/browser/broken-link-checker/tags/2.4.8/legacy/modules/checkers/http.php#L291
- plugins.trac.wordpress.org/browser/broken-link-checker/tags/2.4.8/legacy/modules/checkers/http.php#L432
- plugins.trac.wordpress.org/browser/broken-link-checker/tags/2.4.8/legacy/modules/containers/comment.php#L228
- plugins.trac.wordpress.org/changeset?reponame=&new=3662785%40broken-link-checker%2Ftags%2F2.4.13.1&old=3644192%40broken-link-checker%2Ftags%2F2.4.13
- plugins.trac.wordpress.org/changeset?old_path=%2Fbroken-link-checker/tags/2.4.13&new_path=%2Fbroken-link-checker/tags/2.4.13.1
- All wpmudev CVEs on CVE Radar
- CVEs published in September 2026