CVE-2026-18937: Unknown Broken Link Checker

Critical severity, CVSS 9.0. EPSS: 0.5% chance of exploitation in the next 30 days.

The Broken Link Checker WordPress plugin before 2.4.12 does not limit which query variables it accepts from user input on sites using plain permalinks, allowing unauthenticated users to overwrite arbitrary PHP global variables, and to execute arbitrary code on the server when a classic (non-block) is active.

Affected products

  • Unknown Broken Link Checker: before 2.4.12 (fixed in 2.4.12)

Published 2026-08-19. Last modified 2026-08-26.