CVE-2026-18855 (matched: wordpress)

  • Sunday, 16th August, 2026
  • 10:06am

A security flaw has been identified in the Link Library plugin for WordPress, a tool many sites use to organize and display lists of external links. The issue impacts all versions of the plugin up to and including 7.9.4, and is caused by poor validation of file paths when the plugin deletes files tied to links.

If a specific optional setting for the plugin is turned on (it is disabled by default), attackers who do not need to be logged into your site can exploit this flaw to delete any file on the server that hosts your website. Deleting critical files, such as WordPress's core wp-config.php configuration file, can give attackers full control over your site.

For this exploit to work, a site administrator must have enabled the "Delete local file on link deletion" plugin setting, and then later permanently delete a malicious link submitted by an attacker. This deletion step is a routine task that site moderators regularly perform when managing user-submitted content.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-18855

« Back