CRITICAL
Broken Link Checker
CVE published 2026-08-19
CVE-2026-18937
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T06:17:38.847Z and has not been modified since then. This critical vulnerability in the Broken Link Checker WordPress plugin before version 2.4.12 allows unauthenticated users to overwrite arbitrary PHP global variables and execute arbitrary code on the server when a classic theme is active. The v [truncated]