What is CVE-2026-16532?
The Link Library WordPress plugin versions prior to 7.9.3 fail to properly sanitise and escape user-supplied values before using them in SQL queries, leading to unauthenticated SQL injection attacks. Affected WordPress sites should immediately update the plugin to the latest version.
Azərbaycanca: Link Library WordPress plaginin 7.9.3-dən əvvəlki versiyalarında istifadəçi tərəfindən təqdim edilən dəyər SQL sorğusunda istifadə edilməzdən əvvəl düzgün təmizlənmədiyi (sanitise) üçün autentifikasiya olunmamış SQL injection hücumlarına imkan verir. WordPress saytları bu zəiflikdən təsirlənə bilər, plagin dərhal ən son versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which plugin is affected by CVE-2026-16532?
This vulnerability affects the Link Library WordPress plugin.
To which version should the plugin be updated to protect against CVE-2026-16532?
The plugin should be updated to version 7.9.3 or higher.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.