Skip to content
KitploitKITPLOIT
उपकरणएक्सप्लॉइटब्लॉग
Log in
जमा करें
उपकरणएक्सप्लॉइटब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

फ़ीडसंपर्कगोपनीयता© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
CVE-2026-18937 — Proof-of-concept exploit and lab reproduction pack for CVE-2026-18937, an unauthenticated RCE in the Broken Link Checker WordPress plugin before 2.4.12. | Kitploit
उपकरण/GitHubGitHub/abraxas/cve-2026-18937
Vulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration TestingLearning & EducationRemote Access Tool
GitHubabraxas/cve-2026-18937

CVE-2026-18937

Proof-of-concept exploit and lab reproduction pack for CVE-2026-18937, an unauthenticated RCE in the Broken Link Checker WordPress plugin before 2.4.12.

रिपॉजिटरी देखें
329 दिन पहलेअभी तक समीक्षित नहीं

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
साझा करें
अनुरोधित भाषा में सामग्री उपलब्ध नहीं है। अंग्रेज़ी संस्करण दिखाया जा रहा है।

Abraxas Labs - CVE-2026-18937

abraxaslabs.tech  ·  github.com/abraxas  ·  @abraxas_null  ·  [email protected]  ·  CVE-2026-18937

CVE-2026-18937

Broken Link Checker 2.4.11 - wordpress.org

I am @abraxas_null. Loopback lab. The client is CVE-2026-18937-Abraxas-Labs.py.

Query vars become globals. On plain permalinks, Webhook::parse_request merges $_GET into $wp->query_vars. WP::register_globals copies those keys into $GLOBALS, including $shortcode_tags. A classic theme that runs the_content('[blcpoc]') then call_user_funcs an attacker-named function. 2.4.12 removes the $_GET merge.

CVECVE-2026-18937 · CVE.org
CWECWE-94
CVSSCritical: 9.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
ProductBroken Link Checker
Affectedall versions through 2.4.11 (inclusive)
Patched2.4.12 and later
Authnone
LicenseGNU Affero GPL v3.0
Lab127.0.0.1 only

What an attacker can do

Unauthenticated GET with extra query keys on a site using plain permalinks and a classic theme. Overwrite arbitrary PHP globals. When a shortcode in the content matches, that is RCE in the WordPress process. The lab canary takes no args and echoes a unique string. I am not printing a system recipe.


How I found it

WPScan named query-var injection. I read parse_request, then register_globals, then put [blcpoc] on the front page.

Discover the front page id (id="post-N"), then GET /?page_id=N&shortcode_tags[blcpoc]=poc_witness_18937. The page is still a theme. The function still ran. Do not wait for tiny JSON. This is the_content, not admin-ajax.

Wrong turns: pretty permalinks (plain_permalinks_mode() false, merge skipped); block theme with no [blcpoc] in content; widget query-var tricks (sidebar state reloaded from options); admin-ajax.php.


The lab

Port 8088. Broken Link Checker 2.4.11. Empty permalink_structure. Twenty Twenty-One. mu-plugin canary poc_witness_18937.

  • lab/Dockerfile
  • lab/docker-compose.override.yml
  • lab/docker-compose.yml

Target only 127.0.0.1:8088 (or the loopback you bound).

cd lab
docker compose up --force-recreate
python3 ../CVE-2026-18937-Abraxas-Labs.py

Witness: HTTP body contains POCWitness18937. Homepage without that string is not it.

Ways to lose without learning anything:

  • pretty permalinks
  • block theme, no shortcode in content
  • admin-ajax.php
  • reverse shell / system recipe

The fix

Update Broken Link Checker to 2.4.12 or newer. Re-run CVE-2026-18937-Abraxas-Labs.py against the patched build: POCWitness18937 must not appear.


References

  • CVE-2026-18937 · NVD

  • CVE-2026-18937 · CVE.org

  • wpscan.com/vulnerability/a23b76eb-107d-4e02-8eae-c3c5fa5b003d/

  • github.com/advisories/GHSA-c2xc-88v3-37g2

  • nvd.nist.gov/vuln/detail/CVE-2026-18937

  • wpscan.com/vulnerability/a23b76eb-107d-4e02-8eae-c3c5fa5b003d

  • Plugin directory: broken-link-checker

  • Trac browser: plugins.trac.wordpress.org/broken-link-checker

  • SVN tags: plugins.svn.wordpress.org/broken-link-checker

  • Abraxas Labs: abraxaslabs.tech · github.com/abraxas · @abraxas_null


License

GNU Affero GPL v3.0. See LICENSE.


The client talks to loopback. Using it against systems you do not own is not authorized by Abraxas Labs. No warranty.

abraxaslabs.tech · github.com/abraxas · @abraxas_null

टूल डाउनलोड करें