A security flaw has been identified in the WordPress Link Library plugin, a tool used to organize and display link collections on websites. The issue impacts every version of the plugin up to and including version 7.9.4.
The vulnerability allows unauthenticated attackers (people without valid login credentials for your WordPress site) to delete arbitrary files stored on your web server. If an attacker deletes the correct critical file, such as WordPress’s core configuration file, they can gain full remote control of your website.
For this flaw to be successfully exploited, two specific preconditions must be met: first, the "Delete local file on link deletion" setting in the Link Library plugin must be enabled (this setting is turned off by default for all sites), and second, a user with administrator access to your site must permanently delete a malicious link submitted by an attacker, a common routine moderation action.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-18855