What is CVE-2026-18937?
The vulnerability in the Broken Link Checker WordPress plugin (CVE-2026-18937) allows unauthenticated users on sites with plain permalinks to overwrite arbitrary PHP global variables, potentially leading to arbitrary code execution on the server. Users should immediately update the plugin to version 2.4.12 or later.
Azərbaycanca: Broken Link Checker WordPress plaginindəki boşluq (CVE-2026-18937) sadə keçid strukturundan (plain permalinks) istifadə edən saytlarda autentifikasiya olunmamış istifadəçilərə ixtiyari PHP qlobal dəyişənlərini üzərinə yazmağa imkan verir ki, bu da serverdə ixtiyari kod icrasına (arbitrary code execution) səbəb ola bilər. Plagindən istifadə edən istifadəçilər dərhal versiya 2.4.12 və ya daha yuxarı versiyaya yeniləmə etməlidirlər.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
Which WordPress site configuration is affected by CVE-2026-18937?
This vulnerability affects WordPress sites using plain permalinks.
What can CVE-2026-18937 lead to on the server via the Broken Link Checker plugin?
This vulnerability allows unauthenticated users to overwrite arbitrary PHP global variables, which can lead to arbitrary code execution on the server.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.