
Proof-of-concept exploit and lab reproduction pack for CVE-2026-18937, an unauthenticated RCE in the Broken Link Checker WordPress plugin before 2.4.12.
abraxaslabs.tech · github.com/abraxas · @abraxas_null · [email protected] · CVE-2026-18937
Broken Link Checker 2.4.11 - wordpress.org
I am @abraxas_null. Loopback lab. The client is CVE-2026-18937-Abraxas-Labs.py.
Query vars become globals. On plain permalinks, Webhook::parse_request merges $_GET into $wp->query_vars. WP::register_globals copies those keys into $GLOBALS, including $shortcode_tags. A classic theme that runs the_content('[blcpoc]') then call_user_funcs an attacker-named function. 2.4.12 removes the $_GET merge.
| CVE | CVE-2026-18937 · CVE.org |
| CWE | CWE-94 |
| CVSS | Critical: 9.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H |
| Product | Broken Link Checker |
| Affected | all versions through 2.4.11 (inclusive) |
| Patched | 2.4.12 and later |
| Auth | none |
| License | GNU Affero GPL v3.0 |
| Lab | 127.0.0.1 only |
Unauthenticated GET with extra query keys on a site using plain permalinks and a classic theme. Overwrite arbitrary PHP globals. When a shortcode in the content matches, that is RCE in the WordPress process. The lab canary takes no args and echoes a unique string. I am not printing a system recipe.
WPScan named query-var injection. I read parse_request, then register_globals, then put [blcpoc] on the front page.
Discover the front page id (id="post-N"), then GET /?page_id=N&shortcode_tags[blcpoc]=poc_witness_18937. The page is still a theme. The function still ran. Do not wait for tiny JSON. This is the_content, not admin-ajax.
Wrong turns: pretty permalinks (plain_permalinks_mode() false, merge skipped); block theme with no [blcpoc] in content; widget query-var tricks (sidebar state reloaded from options); admin-ajax.php.
Port 8088. Broken Link Checker 2.4.11. Empty permalink_structure. Twenty Twenty-One. mu-plugin canary poc_witness_18937.
Target only 127.0.0.1:8088 (or the loopback you bound).
cd lab
docker compose up --force-recreate
python3 ../CVE-2026-18937-Abraxas-Labs.py
Witness: HTTP body contains POCWitness18937. Homepage without that string is not it.
Ways to lose without learning anything:
admin-ajax.phpsystem recipeUpdate Broken Link Checker to 2.4.12 or newer. Re-run CVE-2026-18937-Abraxas-Labs.py against the patched build: POCWitness18937 must not appear.
wpscan.com/vulnerability/a23b76eb-107d-4e02-8eae-c3c5fa5b003d/
wpscan.com/vulnerability/a23b76eb-107d-4e02-8eae-c3c5fa5b003d
Plugin directory: broken-link-checker
Trac browser: plugins.trac.wordpress.org/broken-link-checker
Abraxas Labs: abraxaslabs.tech · github.com/abraxas · @abraxas_null
GNU Affero GPL v3.0. See LICENSE.
The client talks to loopback. Using it against systems you do not own is not authorized by Abraxas Labs. No warranty.