The Link Library plugin for WordPress (versions up to 7.9.4) contains an arbitrary file deletion vulnerability caused by insufficient path validation in the ll_delete_link_fields function. When the 'Delete local file on link deletion' option is enabled, unauthenticated attackers can submit malicious links that, once deleted by an administrator during routine moderation, trigger deletion of critical files such as wp-config.php, potentially leading to full remote code execution.
Updated Aug 17, 2026 · CVSS 9.1