LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2026-18937

Published
CVSS9
Severitycritical
WeaknessCWE-94
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Description

The Broken Link Checker WordPress plugin before 2.4.12 does not limit which query variables it accepts from user input on sites using plain permalinks, allowing unauthenticated users to overwrite arbitrary PHP global variables, and to execute arbitrary code on the server when a classic (non-block) is active.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-18937

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-18937.