{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/link-library/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-18855"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Link Library"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe Link Library plugin for WordPress (versions 7.9.4 and earlier) contains a critical security flaw in the ll_delete_link_fields function. The vulnerability stems from insufficient file path validation, allowing an unauthenticated attacker to supply a crafted path that the application will treat as a target for deletion.\u003c/p\u003e\n\u003cp\u003eFor the attack to succeed, the administrator must have enabled the 'Delete local file on link deletion' feature, which is disabled by default. Once enabled, an attacker submits a malicious link to the application. When a site administrator performs the routine moderation task of permanently deleting that link, the application executes a deletion command against the attacker-supplied file path rather than the legitimate link file. Successful exploitation leads to the loss of critical system files, such as wp-config.php, which can subsequently be leveraged to achieve remote code execution (RCE) by forcing a reinstallation of the WordPress environment.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker discovers a WordPress site using the Link Library plugin.\u003c/li\u003e\n\u003cli\u003eAttacker verifies the 'Delete local file on link deletion' option is active by submitting a link or observing site behavior.\u003c/li\u003e\n\u003cli\u003eAttacker submits a new link containing a path traversal payload or a path to a critical system file (e.g., wp-config.php) in the link's metadata/fields.\u003c/li\u003e\n\u003cli\u003eThe site administrator logs into the WordPress dashboard.\u003c/li\u003e\n\u003cli\u003eThe administrator views the list of pending or submitted links.\u003c/li\u003e\n\u003cli\u003eThe administrator selects the malicious link and triggers a permanent delete operation.\u003c/li\u003e\n\u003cli\u003eThe ll_delete_link_fields function executes the deletion using the attacker-controlled path.\u003c/li\u003e\n\u003cli\u003eCritical files are removed, destabilizing the application and potentially facilitating RCE.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in the permanent deletion of arbitrary files on the hosting server. If key files such as wp-config.php are deleted, the integrity of the WordPress installation is compromised, often resulting in complete service downtime or an opportunity for the attacker to reconfigure the database credentials to gain full administrative access.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized, concrete actions for detection engineering teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the Link Library plugin to the latest version immediately to resolve CVE-2026-18855.\u003c/li\u003e\n\u003cli\u003eDisable the 'Delete local file on link deletion' setting in the Link Library configuration if it is not strictly required for business operations.\u003c/li\u003e\n\u003cli\u003eAudit administrative moderation logs to identify abnormal link deletion patterns.\u003c/li\u003e\n\u003cli\u003eImplement File Integrity Monitoring (FIM) on the web root to detect unexpected deletion events targeting wp-config.php or other sensitive system files.\u003c/li\u003e\n\u003cli\u003eMonitor web server error logs for recurrent file access failures following link deletion tasks.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-15T20:20:24Z","date_published":"2026-08-15T20:20:24Z","id":"https://feed.craftedsignal.io/briefs/2026-08-link-library-arbitrary-file-deletion/","summary":"An unauthenticated arbitrary file deletion vulnerability in the Link Library WordPress plugin (CVE-2026-18855) allows attackers to trigger server-side file removal via manipulated input during standard administrative moderation.","title":"Arbitrary File Deletion in Link Library Plugin for WordPress","url":"https://feed.craftedsignal.io/briefs/2026-08-link-library-arbitrary-file-deletion/"}],"language":"en","title":"CraftedSignal Threat Feed - Link Library","version":"https://jsonfeed.org/version/1.1"}