CVE-2026-18937
Broken Link Checker < 2.4.12 - Unauthenticated RCE via Query Variable Injection
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Broken Link Checker WordPress plugin before 2.4.12 does not limit which query variables it accepts from user input on sites using plain permalinks, allowing unauthenticated users to overwrite arbitrary PHP global variables, and to execute arbitrary code on the server when a classic (non-block) is active.
| Vendor | unknown |
| Product | broken link checker |
| Published | Aug 19, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown broken link checker
Be the first to know when new unknown vulnerabilities affecting unknown broken link checker are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Broken Link Checker
0 < 2.4.12
References
Credits
Jakub Herman WPScan