Link Library WordPress Plugin Vulnerability: Critical Arbitrary File Deletion
- Severity
- CRITICAL
- CVSS
- 9.1
- Affected component
- link library (wordpress)
- Patched version
- Not yet available
The Link Library plugin for WordPress is under investigation for a critical vulnerability that could allow arbitrary file deletion and remote code execution.
What happened
The Link Library plugin for WordPress is reportedly vulnerable to arbitrary file deletion due to insufficient file path validation. This vulnerability, tracked as CVE-2026-18855, can potentially lead to remote code execution if an attacker manages to delete a critical file such as wp-config.php. Exploitation requires specific plugin settings and actions by the attacker, including the 'Delete local file on link deletion' option being enabled and the attacker-submitted link being permanently deleted.
The vulnerability affects all versions of the Link Library plugin up to and including 7.9.4. There is no official fix published yet, and the vulnerability is not reported to be exploited in the wild at this time. Users are advised to monitor the situation closely and review server logs for any signs of exploitation.
What to do about it
- Disable the 'Delete local file on link deletion' option in the Link Library plugin settings if it is not needed.
- Monitor for any suspicious file deletions on your server.
- Review server logs for any signs of potential exploitation.
- No official fix has been published yet. Monitor the sources below for updates on a patched version.
How 0Day would have caught this
link library is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
You are reportedly affected if you are using the Link Library plugin for WordPress in versions <= 7.9.4.
What should I do right now?
Disable the 'Delete local file on link deletion' option in the Link Library plugin settings if it is not needed. Monitor for any suspicious file deletions and review server logs for potential exploitation.
Is there a patched version available?
No official fix has been published yet. Monitor the sources below for updates on a patched version.
Where can I get more information?
Consult the primary sources listed below for the most up-to-date information on CVE-2026-18855.