A security flaw has been found in the Link Library plugin for WordPress, affecting all versions up to and including 7.9.4. This issue could let unauthenticated attackers delete files stored on your website's server, but only if the plugin's "Delete local file on link deletion" setting is turned on. This setting is disabled by default for all sites using the plugin.
If that setting is enabled, a common routine task for site administrators (permanently removing a link submitted by a visitor as part of content moderation) can be exploited to delete critical site files, such as the file that stores your site's core configuration. In these cases, deleting the right file could allow an attacker to take full control of your website.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-18855