The Link Library plugin for WordPress has a security flaw affecting all versions up to and including 7.9.4. This issue is caused by the plugin not properly validating file paths when processing link deletions, which could allow unauthenticated attackers to delete files stored on your web server.
This risk only applies if you have turned on the plugin’s optional “Delete local file on link deletion” setting, which is disabled by default. For the flaw to be exploited, an attacker would first need to submit a malicious link to your site, and an administrator would then need to permanently delete that link as part of routine site moderation.
If an attacker is able to delete certain critical server files, such as WordPress’s core wp-config.php file, they can gain full control over your website.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-18855