A security vulnerability has been found in the Link Library plugin for WordPress, a tool used to manage and display link lists on WordPress sites. All versions of this plugin up to and including version 7.9.4 are affected. The flaw allows unauthenticated third parties to delete arbitrary files stored on your web server under specific conditions. If an attacker deletes a critical core file, such as WordPress's main configuration file, this can give them full remote control of your website. For this vulnerability to be exploited, two conditions must be met: first, the plugin's "Delete local file on link deletion" setting must be enabled (this option is turned off by default for all sites), and second, a site administrator must permanently delete a malicious link submitted by the attacker, which is a standard routine moderation task for most site managers.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-18855