Pluginrx develops a narrowly scoped WordPress plugin focused on identifying and notifying about broken links, presenting a modestly scaled attack surface typical of lightweight content-management extensions. The recurring vulnerability signal centers on server-side request forgery, which reflects the plugin's need to perform outbound link validation and the input-handling risks inherent in that function. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pluginrx over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-6851MEDIUM The Broken Link Notifier plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.3.0 via the ajax_blinks() function which ultimate | Jul 11, 2025 | 6.5 | 29 | NO | YES |
CVE-2026-25408MEDIUM Missing Authorization vulnerability in PluginRx Broken Link Notifier broken-link-notifier allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects | Feb 19, 2026 | 5.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pluginrx.
Media articles that mention a CVE ID that affects a product developed by Pluginrx — matched by CVE ID, not by vendor name.