CSV Injection Vulnerability in Broken Link Notifier Plugin for WordPress
CVE-2025-6838
4.1MEDIUM
What is CVE-2025-6838?
The Broken Link Notifier plugin for WordPress is susceptible to CSV Injection across all versions up to and including 1.3.0. This vulnerability allows authenticated attackers, with Contributor-level access or higher, to insert untrusted data into CSV files exported by the plugin. When these files are downloaded and subsequently opened on a system that has vulnerable settings, it may lead to arbitrary code execution, posing significant risks for users who rely on this functionality.
Affected Version(s)
Broken Link Notifier * <= 1.3.0