XSS Vulnerability in Broken Link Manager Plugin for WordPress
CVE-2015-9453
6.1MEDIUM
What is CVE-2015-9453?
The Broken Link Manager plugin for WordPress prior to version 0.6.0 is susceptible to a Cross-Site Scripting (XSS) vulnerability. This flaw allows attackers to inject malicious scripts via the HTTP Referer or User-Agent headers when users request a non-existent URL. If successfully exploited, this vulnerability can compromise the security of the affected WordPress site, allowing attackers to execute harmful scripts in the context of the user's session.