Skip to content
KitploitKITPLOIT
أدواتعمليات الاستغلالالمدونة
Log in
إرسال
أدواتعمليات الاستغلالالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

الخلاصاتاتصالالخصوصية© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
CVE-2026-18937 — Proof-of-concept exploit and lab reproduction pack for CVE-2026-18937, an unauthenticated RCE in the Broken Link Checker WordPress plugin before 2.4.12. | Kitploit
أدوات/GitHubGitHub/abraxas/cve-2026-18937
Vulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration TestingLearning & EducationRemote Access Tool
GitHubabraxas/cve-2026-18937

CVE-2026-18937

Proof-of-concept exploit and lab reproduction pack for CVE-2026-18937, an unauthenticated RCE in the Broken Link Checker WordPress plugin before 2.4.12.

عرض المستودع
32منذ 9 أياملم تتم المراجعة بعد

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة
المحتوى غير متوفر باللغة المطلوبة. عرض النسخة الإنجليزية.

Abraxas Labs - CVE-2026-18937

abraxaslabs.tech  ·  github.com/abraxas  ·  @abraxas_null  ·  [email protected]  ·  CVE-2026-18937

CVE-2026-18937

Broken Link Checker 2.4.11 - wordpress.org

I am @abraxas_null. Loopback lab. The client is CVE-2026-18937-Abraxas-Labs.py.

Query vars become globals. On plain permalinks, Webhook::parse_request merges $_GET into $wp->query_vars. WP::register_globals copies those keys into $GLOBALS, including $shortcode_tags. A classic theme that runs the_content('[blcpoc]') then call_user_funcs an attacker-named function. 2.4.12 removes the $_GET merge.

CVECVE-2026-18937 · CVE.org
CWECWE-94
CVSSCritical: 9.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
ProductBroken Link Checker
Affectedall versions through 2.4.11 (inclusive)
Patched2.4.12 and later
Authnone
LicenseGNU Affero GPL v3.0
Lab127.0.0.1 only

What an attacker can do

Unauthenticated GET with extra query keys on a site using plain permalinks and a classic theme. Overwrite arbitrary PHP globals. When a shortcode in the content matches, that is RCE in the WordPress process. The lab canary takes no args and echoes a unique string. I am not printing a system recipe.


How I found it

WPScan named query-var injection. I read parse_request, then register_globals, then put [blcpoc] on the front page.

Discover the front page id (id="post-N"), then GET /?page_id=N&shortcode_tags[blcpoc]=poc_witness_18937. The page is still a theme. The function still ran. Do not wait for tiny JSON. This is the_content, not admin-ajax.

Wrong turns: pretty permalinks (plain_permalinks_mode() false, merge skipped); block theme with no [blcpoc] in content; widget query-var tricks (sidebar state reloaded from options); admin-ajax.php.


The lab

Port 8088. Broken Link Checker 2.4.11. Empty permalink_structure. Twenty Twenty-One. mu-plugin canary poc_witness_18937.

  • lab/Dockerfile
  • lab/docker-compose.override.yml
  • lab/docker-compose.yml

Target only 127.0.0.1:8088 (or the loopback you bound).

cd lab
docker compose up --force-recreate
python3 ../CVE-2026-18937-Abraxas-Labs.py

Witness: HTTP body contains POCWitness18937. Homepage without that string is not it.

Ways to lose without learning anything:

  • pretty permalinks
  • block theme, no shortcode in content
  • admin-ajax.php
  • reverse shell / system recipe

The fix

Update Broken Link Checker to 2.4.12 or newer. Re-run CVE-2026-18937-Abraxas-Labs.py against the patched build: POCWitness18937 must not appear.


References

  • CVE-2026-18937 · NVD

  • CVE-2026-18937 · CVE.org

  • wpscan.com/vulnerability/a23b76eb-107d-4e02-8eae-c3c5fa5b003d/

  • github.com/advisories/GHSA-c2xc-88v3-37g2

  • nvd.nist.gov/vuln/detail/CVE-2026-18937

  • wpscan.com/vulnerability/a23b76eb-107d-4e02-8eae-c3c5fa5b003d

  • Plugin directory: broken-link-checker

  • Trac browser: plugins.trac.wordpress.org/broken-link-checker

  • SVN tags: plugins.svn.wordpress.org/broken-link-checker

  • Abraxas Labs: abraxaslabs.tech · github.com/abraxas · @abraxas_null


License

GNU Affero GPL v3.0. See LICENSE.


The client talks to loopback. Using it against systems you do not own is not authorized by Abraxas Labs. No warranty.

abraxaslabs.tech · github.com/abraxas · @abraxas_null

تنزيل الأداة