WORDPRESS · AUGUST 2026 · EARLY WARNING

Link Library WordPress Plugin Vulnerability: Critical Arbitrary File Deletion

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity
CRITICAL
CVSS
9.1
Affected component
link library (wordpress)
Patched version
Not yet available
CVE-2026-18855

The Link Library plugin for WordPress is under investigation for a critical vulnerability that could allow arbitrary file deletion and remote code execution.

What happened

The Link Library plugin for WordPress is reportedly vulnerable to arbitrary file deletion due to insufficient file path validation. This vulnerability, tracked as CVE-2026-18855, can potentially lead to remote code execution if an attacker manages to delete a critical file such as wp-config.php. Exploitation requires specific plugin settings and actions by the attacker, including the 'Delete local file on link deletion' option being enabled and the attacker-submitted link being permanently deleted.

The vulnerability affects all versions of the Link Library plugin up to and including 7.9.4. There is no official fix published yet, and the vulnerability is not reported to be exploited in the wild at this time. Users are advised to monitor the situation closely and review server logs for any signs of exploitation.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If link library is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

You are reportedly affected if you are using the Link Library plugin for WordPress in versions <= 7.9.4.

What should I do right now?

Disable the 'Delete local file on link deletion' option in the Link Library plugin settings if it is not needed. Monitor for any suspicious file deletions and review server logs for potential exploitation.

Is there a patched version available?

No official fix has been published yet. Monitor the sources below for updates on a patched version.

Where can I get more information?

Consult the primary sources listed below for the most up-to-date information on CVE-2026-18855.

Sources

Join the 0Day waitlist →

← Back to all threats