HomeSecurityCVE-2026-18855: Critical vulnerability in WordPress Link Library

CVE-2026-18855: Critical vulnerability in WordPress Link Library

A critical vulnerability in the WordPress Link Library allows unauthenticated attackers to delete arbitrary files from the server. CVE-2026-18855 affects all versions up to 7.9.4 and could, under certain conditions, even lead to remote code execution.

CVE-2026-18855 WordPress Link Library

The CVE Alert rates the issue at CVSS 9.1 and is rated critical. NVD still shows limited evidence as the entry is not fully enriched, so administrators should treat the report with caution.

See also: W3 Total Cache XSS: Critical vulnerability in WordPress websites

How the CVE-2026-18855 WordPress Link Library works

The issue is in the ll_delete_link_fields, which handles local file deletion when a link is removed from the library. Insufficient path validation allows the plugin to accept a file location that should not be accessible.

The attack does not require an administrator account. The attacker submits a link and waits for the administrator to permanently delete it. The scenario is only possible when the local file deletion setting, which is disabled by default.

Arbitrary deletion of files in WordPress

This combination of conditions reduces the likelihood of accidental exploitation, but does not eliminate the risk. On sites where the setting was enabled for operational needs, a seemingly routine link monitoring action can cause a catastrophic deletion.

From file deletion to remote execution

Arbitrary deletion is not necessarily limited to plugin files. If a critical file, such as wp-config.php, is affected, the consequence could be remote code execution or complete loss of control of the installation. The exact chain depends on the server permissions and file structure.

Version 7.9.5 is listed as the current version on the Link Library page on WordPress.org. The listing generally lists fixes for potential security issues, without explicitly linking the specific CVE to the version. For this, upgrading is the first step, but it also requires administrator review.

The critical point is the relationship between content submission and the moderation process. The attacker does not need to convince the administrator to open a file or execute a command; they simply create an entry that will pass through the usual audit flow. The final deletion, if it is permanent, triggers the function that links the entry to the local file.

The success of the attack depends on the precise configuration of the website. This means that not every installation should be considered equally vulnerable, but also that disabling the setting should not be postponed. Teams managing multiple websites need to centrally control the settings, rather than relying on manual confirmation.

Because the CVE is so recent, the available information may be enriched with new technical details, fixes, or guidance from the add-on creator. Until then, upgrading to 7.9.5, confirming that the dangerous option is turned off, and looking for suspicious actions is the most prudent approach.

See also: New WordPress Pre-Auth XSS may lead to PHP code execution

WordPress plugin attack chain

What should administrators do?

Administrators should immediately upgrade the WordPress Link Library to version 7.9.5 or later, if available, and check the update history to confirm. Until a clear technical announcement is made, the local file deletion option should remain disabled.

At the same time, it is useful to check the logs for new link submissions, deletions, and unusual changes to wp-config.php. A recent off-server backup, restricted file permissions, and integrity checking can limit the consequences.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The SecNews technical team also recommends avoiding enabling settings that automatically delete files when there is no clear business need. In case of suspicious activity, the website should be temporarily isolated and examined by a specialist, without deleting the available logs.

Audits should not be limited to the plugin version alone. It is worth recording accounts with link submission permissions, recent permanent deletions, and changes to the WordPress Link Library settings to detect any unusual sequence of actions in a timely manner.

See also: CVE-2026-19899 SourceCodester: Critical SQL injection in clock system

The CVE-2026-18855 WordPress Link Library shows that even a link management feature can be turned into a serious entry point. Installing the latest version, disabling the dangerous option, and monitoring for deletions are the key measures until more official technical details are published.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS