CVE-2026-18855Disclosure

LOWCVSS 9.1 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The Link Library plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ll_delete_link_fields function in all versions up to, and including, 7.9.4 This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). Exploitation requires the administrator to have enabled the 'Delete local file on link deletion' plugin option (disabled by default) and to subsequently permanently delete the attacker-submitted link, which is a routine moderation action.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-08-15); latest day: 2
  • 5 total mentions across 2 days

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-08-15: 3Mentions · 2026-08-16: 2Patch / Workaround · 2026-08-16: 2Technical Details · 2026-08-15: 2Technical Details · 2026-08-16: 208-1508-16
Signal classification2 categories
Disclosure
480.0%
General
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-08-153
Disclosure2General1
2026-08-162
Disclosure2
Full discourse5 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-18855 The Link Library plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ll_delete_link_fields function in all v… https://www.cve.org/CVERecord?id=CVE-2026-18855

    Post summary

    The text discloses that the Link Library WordPress plugin has an arbitrary file deletion vulnerability caused by insufficient path validation, but provides no PoC, exploit, or patch information.

    000102.0K
    57.9K followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Disclosure

    CVE-2026-18855 - Critical RCE in WordPress Link Library plugin. Unauthenticated arbitrary file deletion via ll_delete_link_fields. CVSS 9.1. Patch under review. Update immediately. #CVE #WordPress #infosec https://www.valtersit.com/cve/CVE-2026-18855/ #CVE #infosec #SysAdmin #cybersecurity #Linux #infosec #devsecops #devops #developer #sysadmin #100daysofcode #git #github #gitlab #redteam #blueteam #ethicalhacker #ethicalhacking #cybersecurityawareness #cybersecurity #cybersecuritynews #cybersecuritytips #python #hacker #linux #kali #ubuntu #debian #ukraine #spain #ireland #unitedkingdom #canada #finland #estonia #lithuania #ireland #hungary #denmark #norway #malta #mexico

    Post summary

    The tweet announces the critical CVE-2026-18855 affecting the WordPress Link Library plugin, details an unauthenticated remote code execution allowing file deletion, and calls for an immediate update as a patch is under review.

    0000073
    1.0K followersView on X
  • ADK Cyber@ADKCyber
    Disclosure

    WordPress Link Library plugin vulnerable to arbitrary file deletion (CVE-2026-18855, CVSS 9.1) in versions up to 7.9. Check and update if in use: https://nvd.nist.gov/vuln/detail/CVE-2026-18855 via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability #AI #MachineLearning https://t.co/rdPKKgq0ci

    Post summary

    CVE-2026-18855 allows arbitrary file deletion in WordPress Link Library plugins (up to v7.9) and is rated CVSS 9.1; users are advised to check and update to address the vulnerability.

    0000062
    93 followersView on X
  • SecNews@SecNews_GR
    General

    CVE-2026-18855: Κρίσιμη ευπάθεια στο Link Library WordPress https://secn.ws/HcXAAU

    Post summary

    The post announces a critical vulnerability in the WordPress Link Library plugin (CVE‑2026‑18855) but provides no further technical details, fixes, or evidence of exploitation.

    00000206
    7.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-18855 The Link Library plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ll_delete_link_fields function in all v… https://www.cve.org/CVERecord?id=CVE-2026-18855 ----- Traducción: CVE-2026-18855 El … https://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑18855 for the WordPress Link Library plugin, outlining an arbitrary file deletion flaw, but provides no PoC, exploit, active use, patch, or false‑positive claim.

    0000033
    98 followersView on X

Explore more