CVE-2026-18937

The Broken Link Checker WordPress plugin before 2.4.12 does not limit which query variables it accepts from user input on sites using plain permalinks, allowing unauthenticated users to overwrite arbitrary PHP global variables, and to execute arbitrary code on the server when a classic (non-block) is active.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-19 06:17

Updated : 2026-08-26 16:30


NVD link : CVE-2026-18937

Mitre link : CVE-2026-18937

CVE.ORG link : CVE-2026-18937


JSON object : View

Products Affected

No product.

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')