CVE-2026-18855 (matched: wordpress)

  • Sunday, 16th August, 2026
  • 22:05pm

A security flaw has been found in the Link Library plugin for WordPress, affecting all versions up to and including 7.9.4. This flaw allows attackers who are not logged into your website to delete any file stored on your site's server, but only under specific conditions.

For the flaw to be exploited, the plugin's "Delete local file on link deletion" setting must be enabled (this option is turned off by default). The attacker also needs a site administrator to permanently delete a link the attacker submitted, which is a common routine moderation task for most WordPress sites.

If attackers delete the right critical file, such as WordPress's core wp-config.php configuration file, they can gain full remote control of your website, allowing them to run unauthorized code on your server.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-18855

« Back