Ghostwire

CVE-2026-18937: The Broken Link Checker WordPress plugin before 2.4.12 does not limit which query variables it accepts from user input...

CRITICAL CVSS 0.0

Published: August 19, 2026 | Last Modified: August 19, 2026

Description

The Broken Link Checker WordPress plugin before 2.4.12 does not limit which query variables it accepts from user input on sites using plain permalinks, allowing unauthenticated users to overwrite arbitrary PHP global variables, and to execute arbitrary code on the server when a classic (non-block) is active.

Ghostwire Analysis — What This Means Practically

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Security Coverage (1 articles)

References