Arbitrary File Deletion in Link Library Plugin for WordPress
CVE-2026-18855

9.1CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
15 August 2026

What is CVE-2026-18855?

The Link Library plugin for WordPress is susceptible to arbitrary file deletion triggered by inadequate file path validation within the ll_delete_link_fields function. This vulnerability affects all versions up to and including 7.9.4, permitting unauthenticated attackers to remove arbitrary files from the server, potentially leading to severe consequences like remote code execution. Successful exploitation necessitates that the plugin option 'Delete local file on link deletion' be enabled, which is typically disabled by default. Once this option is active, an attacker can cause file deletions by submitting a link and triggering the routine action of permanent deletion by an administrator.

Affected Version(s)

Link Library 0 <= 7.9.4

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

nudien
.