CRITICAL 9 CVE-2026-18937 Published 19 Aug 2026

WordPress Broken Link Checker Plugin Code Execution Bug

Worried this affects one of your servers?

The Broken Link Checker WordPress plugin, before version 2.4.12, has a vulnerability that allows unauthenticated users to overwrite arbitrary PHP global variables and execute arbitrary code on the server.

This is possible due to the plugin not limiting which query variables it accepts from user input on sites using plain permalinks.

Impact: This vulnerability can be exploited when a classic (non-block) is active.

Reference: CVE-2026-18937 on NVD

← Back to Security News