CVE-2026-18937: CWE-94 Improper Control of Generation of Code ('Code Injection') in Broken Link Checker
CVE-2026-18937 is a critical code injection vulnerability in the Broken Link Checker WordPress plugin before version 2.4.12. It allows unauthenticated users on sites using plain permalinks to overwrite arbitrary PHP global variables and execute arbitrary code on the server when a classic (non-block) editor is active.
AI Analysis
Technical Summary
The Broken Link Checker WordPress plugin versions prior to 2.4.12 do not properly restrict which query variables are accepted from user input on sites using plain permalinks. This flaw enables unauthenticated attackers to overwrite PHP global variables, leading to arbitrary code execution on the server when the classic editor is active. The vulnerability is classified as CWE-94 (Improper Control of Generation of Code) and has a CVSS 3.1 base score of 9.0, indicating critical severity with network attack vector, high attack complexity, no privileges required, no user interaction, and impacts on confidentiality, integrity, and availability.
Potential Impact
Successful exploitation allows unauthenticated attackers to execute arbitrary code on the server, potentially leading to full compromise of the affected WordPress site. This includes complete control over site content, data, and server resources.
Mitigation Recommendations
Upgrade the Broken Link Checker plugin to version 2.4.12 or later, which addresses this vulnerability. No other mitigation or temporary fix is indicated. Patch status is confirmed by the version boundary provided.
CVE-2026-18937: CWE-94 Improper Control of Generation of Code ('Code Injection') in Broken Link Checker
Description
CVE-2026-18937 is a critical code injection vulnerability in the Broken Link Checker WordPress plugin before version 2.4.12. It allows unauthenticated users on sites using plain permalinks to overwrite arbitrary PHP global variables and execute arbitrary code on the server when a classic (non-block) editor is active.
CVSS v3.1
Score 9.0critical
Affected software
Broken Link Checker
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Broken Link Checker WordPress plugin versions prior to 2.4.12 do not properly restrict which query variables are accepted from user input on sites using plain permalinks. This flaw enables unauthenticated attackers to overwrite PHP global variables, leading to arbitrary code execution on the server when the classic editor is active. The vulnerability is classified as CWE-94 (Improper Control of Generation of Code) and has a CVSS 3.1 base score of 9.0, indicating critical severity with network attack vector, high attack complexity, no privileges required, no user interaction, and impacts on confidentiality, integrity, and availability.
Potential Impact
Successful exploitation allows unauthenticated attackers to execute arbitrary code on the server, potentially leading to full compromise of the affected WordPress site. This includes complete control over site content, data, and server resources.
Mitigation Recommendations
Upgrade the Broken Link Checker plugin to version 2.4.12 or later, which addresses this vulnerability. No other mitigation or temporary fix is indicated. Patch status is confirmed by the version boundary provided.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-08-05T12:42:03.011Z
- State
- PUBLISHED
Threat ID: 6a854e93c6e8be033248b29b
Added to database: 08/19/2026, 06:34:59 UTC
Last enriched: 09/11/2026, 09:47:23 UTC
Last updated: 10/02/2026, 14:46:05 UTC
Views: 164
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.