What is CVE-2026-18855?
The Link Library plugin for WordPress up to version 7.9.4 is vulnerable to arbitrary file deletion due to insufficient file path validation in the ll_delete_link_fields function. This allows unauthenticated attackers to delete arbitrary files on the server, potentially disrupting site operations or destroying critical system files.
Azərbaycanca: WordPress üçün Link Library pluginin 7.9.4-ə qədər olan versiyalarında ll_delete_link_fields funksiyasında fayl yolu yoxlamasının zəif olması səbəbindən autentifikasiya olunmamış hücumçular serverdə ixtiyari faylları silə bilər. Bu, saytın işini pozmaq və ya mühüm sistem fayllarını məhv etmək üçün istifadə oluna bilər.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Which versions of the Link Library plugin for WordPress are vulnerable to CVE-2026-18855?
The Link Library plugin for WordPress up to version 7.9.4 is vulnerable to this issue.
What can an unauthenticated attacker do by exploiting CVE-2026-18855?
An unauthenticated attacker can delete arbitrary files on the server.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.