CRITICAL 9.0 NVD
CVE-2026-18937
The Broken Link Checker WordPress plugin before 2.4.12 does not limit which query variables it accepts from user input on sites using plain permalinks, allowing
The Broken Link Checker WordPress plugin before 2.4.12 does not limit which query variables it accepts from user input on sites using plain permalinks, allowing unauthenticated users to overwrite arbitrary PHP global variables, and to execute arbitrary code on the server when a classic (non-block) is active.
References
This critical severity vulnerability with a CVSS score of 9.0 was published on 2026-08-19 via NVD.
Risk Timeline
CVE Disclosed2026-08-19 · 0 days ago
Remediation Resources
Official Advisory
wpscan.com/vulnerability/a23b76eb-107d-4e02-8eae-c3c5fa5b003d/
vulnfeed aggregates 11644 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.