CVE-2026-39466: WordPress Broken Link Checker plugin <= 2.4.7 - SQL Injection vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPMU DEV - Your All-in-One WordPress Platform Broken Link Checker broken-link-checker allows Blind SQL Injection.This issue affects Broken Link Checker: from n/a through <= 2.4.7.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-39466?
CVE-2026-39466 has a medium severity rating due to its potential for SQL Injection exploitation.
How do I fix CVE-2026-39466?
To fix CVE-2026-39466, update the WPMU DEV Broken Link Checker plugin to version 2.4.8 or later.
What is the impact of CVE-2026-39466 on my WordPress site?
CVE-2026-39466 could allow an attacker to execute blind SQL injection attacks, potentially compromising your database.
Which versions of Broken Link Checker are affected by CVE-2026-39466?
CVE-2026-39466 affects WPMU DEV Broken Link Checker plugin versions up to and including 2.4.7.
Is CVE-2026-39466 a common vulnerability?
While SQL Injection vulnerabilities are common, CVE-2026-39466 specifically targets the Broken Link Checker plugin in WordPress installations.