CRITICAL
9 CVE-2026-18937 Published 19 Aug 2026
WordPress Broken Link Checker Plugin Code Execution Bug
Worried this affects one of your servers?
The Broken Link Checker WordPress plugin, before version 2.4.12, has a vulnerability that allows unauthenticated users to overwrite arbitrary PHP global variables and execute arbitrary code on the server.
This is possible due to the plugin not limiting which query variables it accepts from user input on sites using plain permalinks.
Impact: This vulnerability can be exploited when a classic (non-block) is active.
Reference: CVE-2026-18937 on NVD
← Back to Security News