A security vulnerability has been found in the Link Library plugin for WordPress, affecting all versions up to and including 7.9.4. The plugin does not properly validate file paths, which could let unauthenticated attackers delete files stored on your website’s server. If attackers delete the right critical files—such as the core WordPress configuration file wp-config.php—this can lead to full remote control of your site, allowing them to run malicious code on your hosting account. This flaw can only be exploited under two specific conditions: you must have the plugin’s "Delete local file on link deletion" setting enabled (this option is turned off by default), and a site administrator must permanently delete a malicious link submitted by an attacker as part of routine link moderation.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-18855