CVE-2026-18855 (matched: wordpress)

  • Sunday, 16th August, 2026
  • 04:05am

This notice covers a security flaw in the Link Library plugin for WordPress, a tool many site owners use to organize and display collections of links on their websites. The issue impacts all versions of the plugin up to and including 7.9.4, and could let people who do not have login access to your site delete files stored on your website’s hosting server. It is important to note this flaw can only be used if you have manually turned on the plugin’s "Delete local file on link deletion" setting, which is switched off by default. If you have never adjusted this specific setting, your site is not at risk from this vulnerability. If the setting is enabled, an attacker could submit a malicious link to your site. If a site administrator (you or a team member who manages your site’s content) permanently deletes that link as part of routine content moderation, the attacker could exploit the flaw to delete critical files on your server. Removing core WordPress files such as wp-config.php can allow the attacker to take full control of your site, which could lead to stolen visitor data, injected malware, or other harmful activity.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-18855

« Back