← back
CVE-2026-18937criticalCWE-94

Broken Link Checker < 2.4.12 - Unauthenticated RCE via Query Variable Injection

48Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 9epss 0.4%
exploitation probability
0.4%top 67% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The Broken Link Checker WordPress plugin before 2.4.12 does not limit which query variables it accepts from user input on sites using plain permalinks, allowing unauthenticated users to overwrite arbitrary PHP global variables, and to execute arbitrary code on the server when a classic (non-block) is active.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.