Arbitrary File Deletion in Link Library Plugin for WordPress
CVE-2026-18855
9.1CRITICAL
What is CVE-2026-18855?
The Link Library plugin for WordPress is susceptible to arbitrary file deletion triggered by inadequate file path validation within the ll_delete_link_fields function. This vulnerability affects all versions up to and including 7.9.4, permitting unauthenticated attackers to remove arbitrary files from the server, potentially leading to severe consequences like remote code execution. Successful exploitation necessitates that the plugin option 'Delete local file on link deletion' be enabled, which is typically disabled by default. Once this option is active, an attacker can cause file deletions by submitting a link and triggering the routine action of permanent deletion by an administrator.
Affected Version(s)
Link Library 0 <= 7.9.4