๐Ÿ” CVE Alert

CVE-2026-18937

UNKNOWN 0.0

Broken Link Checker < 2.4.12 - Unauthenticated RCE via Query Variable Injection

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Broken Link Checker WordPress plugin before 2.4.12 does not limit which query variables it accepts from user input on sites using plain permalinks, allowing unauthenticated users to overwrite arbitrary PHP global variables, and to execute arbitrary code on the server when a classic (non-block) is active.

Vendor unknown
Product broken link checker
Published Aug 19, 2026
Stay Ahead of the Next One

Get instant alerts for unknown broken link checker

Be the first to know when new unknown vulnerabilities affecting unknown broken link checker are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Broken Link Checker
0 < 2.4.12

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/a23b76eb-107d-4e02-8eae-c3c5fa5b003d/

Credits

Jakub Herman WPScan