CVE-2026-39466 HIGH

CVE-2026-39466: WordPress Broken Link Checker plugin <= 2.4.7 - SQL Injection vulnerability

Vendor Wpmu Dev - Your All-In-One Wordpress Platform
Product Broken Link Checker
Weakness CWE-89 · SQLi
Published April 8, 2026
Last update April 29, 2026

CVSS base score

7.6/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L

What the vulnerability does

01Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPMU DEV - Your All-in-One WordPress Platform Broken Link Checker broken-link-checker allows Blind SQL Injection.This issue affects Broken Link Checker: from n/a through <= 2.4.7.

Explanation of Vulnerability in Simple Terms

02Summary

The Broken Link Checker plugin for WordPress contains a SQL injection vulnerability in versions up to 2.4.7. An attacker with high-level site privileges can craft malicious input to execute arbitrary SQL queries against the site's database. This could allow unauthorized access to sensitive data stored in the database. The vulnerability requires administrator or equivalent access to exploit.

What an attacker can do

03Attacker Capabilities

Read or modify data in the WordPress database by injecting SQL commands.

Potential impact on your site

04Site Impact

An admin account compromised or acting maliciously could extract or alter database contents, including user credentials and site configuration.

Conditions required to exploit

05Prerequisites

Attacker must have administrator or high-level user account on the WordPress site.

Key dates

06Disclosure timeline

April 8, 2026 CVE published
April 29, 2026 Record updated

Related vulnerabilities

08Related CVE