CRITICAL 9.0 NVD

CVE-2026-18937

The Broken Link Checker WordPress plugin before 2.4.12 does not limit which query variables it accepts from user input on sites using plain permalinks, allowing

The Broken Link Checker WordPress plugin before 2.4.12 does not limit which query variables it accepts from user input on sites using plain permalinks, allowing unauthenticated users to overwrite arbitrary PHP global variables, and to execute arbitrary code on the server when a classic (non-block) is active.

References

Published: 2026-08-19 · Source: NVD · Feed updated: 2026-08-20
This critical severity vulnerability with a CVSS score of 9.0 was published on 2026-08-19 via NVD.

Risk Timeline

CVE Disclosed2026-08-19 · 0 days ago

Remediation Resources

vulnfeed aggregates 11644 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.