Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Einreichen
ToolsExploitsBlog
Einreichen

Hacking-, PenTest- und Cybersicherheits-Tools für Ihr Sicherheitsarsenal!

Kitploit ist ein Verzeichnis von Hacking-, Cybersicherheits- und Pentesting-Tools. Entdecken Sie die neuesten Projekt-Updates, um Schwachstellen zu finden, Systeme zu analysieren, Tests zu automatisieren und Ihre Sicherheit zu stärken.

FeedsKontaktDatenschutz© 2026 Kitploit

Tool-Verzeichnis

Kategorien

Alle Kategorien anzeigen
Loading categories
Tools/GitHubGitHub/abraxas/cve-2026-18937
Vulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration TestingLearning & EducationRemote Access Tool
GitHubabraxas/cve-2026-18937

CVE-2026-18937

Proof-of-concept exploit and lab reproduction pack for CVE-2026-18937, an unauthenticated RCE in the Broken Link Checker WordPress plugin before 2.4.12.

Repository anzeigen
32vor 9 TagenNoch nicht geprüft

Beliebteste

Alle anzeigen →

Entdecken Sie die meistgenutzten Tools unserer Community.

Alle Tools erkunden

Durchsuchen Sie unsere Tool-Sammlung

Alle Tools anzeigen →
Teilen
Inhalt in der angeforderten Sprache nicht verfügbar. Englische Version wird angezeigt.

Abraxas Labs - CVE-2026-18937

abraxaslabs.tech  ·  github.com/abraxas  ·  @abraxas_null  ·  [email protected]  ·  CVE-2026-18937

CVE-2026-18937

Broken Link Checker 2.4.11 - wordpress.org

I am @abraxas_null. Loopback lab. The client is CVE-2026-18937-Abraxas-Labs.py.

Query vars become globals. On plain permalinks, Webhook::parse_request merges $_GET into $wp->query_vars. WP::register_globals copies those keys into $GLOBALS, including $shortcode_tags. A classic theme that runs the_content('[blcpoc]') then call_user_funcs an attacker-named function. 2.4.12 removes the $_GET merge.

CVECVE-2026-18937 · CVE.org
CWECWE-94
CVSSCritical: 9.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
ProductBroken Link Checker
Affectedall versions through 2.4.11 (inclusive)
Patched2.4.12 and later
Authnone
LicenseGNU Affero GPL v3.0
Lab127.0.0.1 only

What an attacker can do

Unauthenticated GET with extra query keys on a site using plain permalinks and a classic theme. Overwrite arbitrary PHP globals. When a shortcode in the content matches, that is RCE in the WordPress process. The lab canary takes no args and echoes a unique string. I am not printing a system recipe.


How I found it

WPScan named query-var injection. I read parse_request, then register_globals, then put [blcpoc] on the front page.

Discover the front page id (id="post-N"), then GET /?page_id=N&shortcode_tags[blcpoc]=poc_witness_18937. The page is still a theme. The function still ran. Do not wait for tiny JSON. This is the_content, not admin-ajax.

Wrong turns: pretty permalinks (plain_permalinks_mode() false, merge skipped); block theme with no [blcpoc] in content; widget query-var tricks (sidebar state reloaded from options); admin-ajax.php.


The lab

Port 8088. Broken Link Checker 2.4.11. Empty permalink_structure. Twenty Twenty-One. mu-plugin canary poc_witness_18937.

  • lab/Dockerfile
  • lab/docker-compose.override.yml
  • lab/docker-compose.yml

Target only 127.0.0.1:8088 (or the loopback you bound).

cd lab
docker compose up --force-recreate
python3 ../CVE-2026-18937-Abraxas-Labs.py

Witness: HTTP body contains POCWitness18937. Homepage without that string is not it.

Ways to lose without learning anything:

  • pretty permalinks
  • block theme, no shortcode in content
  • admin-ajax.php
  • reverse shell / system recipe

The fix

Update Broken Link Checker to 2.4.12 or newer. Re-run CVE-2026-18937-Abraxas-Labs.py against the patched build: POCWitness18937 must not appear.


References

  • CVE-2026-18937 · NVD

  • CVE-2026-18937 · CVE.org

  • wpscan.com/vulnerability/a23b76eb-107d-4e02-8eae-c3c5fa5b003d/

  • github.com/advisories/GHSA-c2xc-88v3-37g2

  • nvd.nist.gov/vuln/detail/CVE-2026-18937

  • wpscan.com/vulnerability/a23b76eb-107d-4e02-8eae-c3c5fa5b003d

  • Plugin directory: broken-link-checker

  • Trac browser: plugins.trac.wordpress.org/broken-link-checker

  • SVN tags: plugins.svn.wordpress.org/broken-link-checker

  • Abraxas Labs: abraxaslabs.tech · github.com/abraxas · @abraxas_null


License

GNU Affero GPL v3.0. See LICENSE.


The client talks to loopback. Using it against systems you do not own is not authorized by Abraxas Labs. No warranty.

abraxaslabs.tech · github.com/abraxas · @abraxas_null

Tool herunterladen