plugin

Link Library Vulnerabilities

55 known security issues reported for the Link Library WordPress plugin. Most recent disclosed Aug 14, 2026.

1 critical 3 high 20 medium

Running Link Library on your site? Check whether your installed version is affected.

Scan your site free

Link Library <= 7.9.4 - Unauthenticated Arbitrary File Deletion via link_url Parameter

critical

The Link Library plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ll_delete_link_fields function in all versions up to, and including, 7.9.4 This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to...

CVSS:
9.1
Affected:
up to 7.9.4
Fixed in:
7.9.5
Disclosed:
Aug 14, 2026

CVE-2026-18855 on NVD →

Link Library <= 7.9.3 - Reflected Cross-Site Scripting

medium

The Link Library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 7.9.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully tr...

CVSS:
6.1
Affected:
up to 7.9.3
Fixed in:
7.9.4
Disclosed:
Aug 3, 2026

CVE-2026-16535 on NVD →

Link Library < 7.9.4 - Reflected Cross-Site Scripting

medium

The Link Library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to 7.9.4 (exclusive) due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully tr...

CVSS:
6.1
Affected:
up to 7.9.4
Fixed in:
7.9.4
Disclosed:
Jul 29, 2026

CVE-2026-18197 on NVD →

Link Library <= 7.9.2 - Unauthenticated SQL Injection

high

The Link Library plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 7.9.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries int...

CVSS:
7.5
Affected:
up to 7.9.2
Fixed in:
7.9.3
Disclosed:
Jul 23, 2026

CVE-2026-16532 on NVD →

Link Library <= 7.8.8 - Authenticated (Contributor+) Arbitrary File Deletion

high

The Link Library plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all versions up to, and including, 7.8.8. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete arbitrary files on the server, which can easily lead...

CVSS:
8.1
Affected:
up to 7.8.8
Fixed in:
7.8.9
Disclosed:
Apr 22, 2026

CVE-2026-40779 on NVD →

Link Library <= 7.8.7 - Authenticated (Contributor+) Server-Side Request Forgery

medium

The Link Library plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.8.7. This makes it possible for authenticated attackers, with Contributor-level access and above, to make web requests to arbitrary locations originating from the web application which can be used...

CVSS:
6.4
Affected:
up to 7.8.7
Fixed in:
7.8.8
Disclosed:
Dec 24, 2025

CVE-2025-68600 on NVD →

Link Library [link-library] <= 7.8.4 (unfixed)

unknown

[en] Server-Side Request Forgery (SSRF) vulnerability in Yannick Lefebvre Link Library link-library allows Server Side Request Forgery.This issue affects Link Library: from n/a through <= 7.8.4.

Affected:
up to 7.8.4
Fix:
No patched version reported
Disclosed:
Dec 24, 2025

CVE-2025-68600 on NVD →

Link Library <= 7.8 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Link Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that...

CVSS:
6.4
Affected:
up to 7.8
Fixed in:
7.8.1
Disclosed:
Apr 22, 2025

CVE-2025-46237 on NVD →

Link Library [link-library] < 7.8.1

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yannick Lefebvre Link Library allows Stored XSS. This issue affects Link Library: from n/a through 7.8.

Affected:
up to 7.8.1
Fixed in:
7.8.1
Disclosed:
Apr 22, 2025

CVE-2025-46237 on NVD →

Link Library <= 7.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Link Additional Parameters

medium

The Link Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Link Additional Parameters in all versions up to, and including, 7.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to in...

CVSS:
6.4
Affected:
up to 7.7.3
Fixed in:
7.8
Disclosed:
Apr 4, 2025

CVE-2025-2889 on NVD →

Link Library [link-library] < 7.7.3

unknown

[en] The Link Library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'searchll' parameter in all versions up to, and including, 7.7.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages th...

Affected:
up to 7.7.3
Fixed in:
7.7.3
Disclosed:
Jan 21, 2025

CVE-2024-13404 on NVD →

Link Library <= 7.7.2 - Reflected Cross-Site Scripting

medium

The Link Library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'searchll' parameter in all versions up to, and including, 7.7.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that ex...

CVSS:
6.1
Affected:
up to 7.7.2
Fixed in:
7.7.3
Disclosed:
Jan 20, 2025

CVE-2024-13404 on NVD →

Link Library [link-library] < 7.7.2

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Yannick Lefebvre Link Library allows Reflected XSS.This issue affects Link Library: from n/a through 7.7.1.

Affected:
up to 7.7.2
Fixed in:
7.7.2
Disclosed:
Jul 20, 2024

CVE-2024-38711 on NVD →

Link Library <= 7.7.1 - Reflected Cross-Site Scripting

medium

The Link Library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 7.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully tr...

CVSS:
6.1
Affected:
up to 7.7.1
Fixed in:
7.7.2
Disclosed:
Jul 11, 2024

CVE-2024-38711 on NVD →

Link Library [link-library] < 7.6.4

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Yannick Lefebvre Link Library link-library allows Reflected XSS.This issue affects Link Library: from n/a through 7.6.3.

Affected:
up to 7.6.4
Fixed in:
7.6.4
Disclosed:
Jun 8, 2024

CVE-2024-35687 on NVD →

Link Library <= 7.6.3 - Reflected Cross-Site Scripting

medium

The Link Library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 7.6.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfull...

CVSS:
6.1
Affected:
up to 7.6.3
Fixed in:
7.6.4
Disclosed:
Jun 6, 2024

CVE-2024-35687 on NVD →

Link Library [link-library] < 7.7

unknown

[en] The Link Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'link-library' shortcode in all versions up to, and including, 7.6.11 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with...

Affected:
up to 7.7
Fixed in:
7.7
Disclosed:
May 8, 2024

CVE-2024-4281 on NVD →

Link Library <= 7.6.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via link-library Shortcode

medium

The Link Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'link-library' shortcode in all versions up to, and including, 7.6.11 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contr...

CVSS:
6.4
Affected:
up to 7.6.11
Fixed in:
7.7
Disclosed:
May 7, 2024

CVE-2024-4281 on NVD →

Link Library [link-library] < 7.6.7

unknown

[en] The Link Library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the searchll parameter in all versions up to, and including, 7.6.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that...

Affected:
up to 7.6.7
Fixed in:
7.6.7
Disclosed:
Apr 9, 2024

CVE-2024-2325 on NVD →

Link Library [link-library] < 7.6.1

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yannick Lefebvre Link Library allows Reflected XSS.This issue affects Link Library: from n/a through 7.6.

Affected:
up to 7.6.1
Fixed in:
7.6.1
Disclosed:
Mar 19, 2024

CVE-2024-29123 on NVD →

Link Library <= 7.6 - Reflected Cross-Site Scripting

medium

The Link Library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 7.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully tric...

CVSS:
6.1
Affected:
up to 7.6
Fixed in:
7.6.1
Disclosed:
Mar 16, 2024

CVE-2024-29123 on NVD →

Link Library <= 7.6.6 - Reflected Cross-Site Scripting

medium

The Link Library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the searchll parameter in all versions up to, and including, 7.6.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that exec...

CVSS:
6.1
Affected:
up to 7.6.6
Fixed in:
7.6.7
Disclosed:
Mar 13, 2024

CVE-2024-2325 on NVD →

Link Library [link-library] < 7.6.1

unknown

[en] The Link Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'll_reciprocal' parameter in all versions up to, and including, 7.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages th...

Affected:
up to 7.6.1
Fixed in:
7.6.1
Disclosed:
Feb 20, 2024

CVE-2024-1559 on NVD →

Link Library <= 7.6 - Unauthenticated Stored Cross-Site Scripting

medium

The Link Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'll_reciprocal' parameter in all versions up to, and including, 7.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that wi...

CVSS:
6.5
Affected:
up to 7.6
Fixed in:
7.6.1
Disclosed:
Feb 19, 2024

CVE-2024-1559 on NVD →

Link Library [link-library] < 7.6

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Yannick Lefebvre Link Library.This issue affects Link Library: from n/a through 7.5.13.

Affected:
up to 7.6
Fixed in:
7.6
Disclosed:
Feb 12, 2024

CVE-2024-24875 on NVD →

Link Library [link-library] < 7.6

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yannick Lefebvre Link Library allows Reflected XSS.This issue affects Link Library: from n/a through 7.5.13.

Affected:
up to 7.6
Fixed in:
7.6
Disclosed:
Feb 8, 2024

CVE-2024-24879 on NVD →

Link Library <= 7.5.13 - Reflected Cross-Site Scripting via 'link_price' and 'link_tags'

medium

The Link Library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'link_price' and 'link_tags' parameters in versions up to, and including, 7.5.13 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts...

CVSS:
6.1
Affected:
up to 7.5.13
Fixed in:
7.6
Disclosed:
Feb 5, 2024

CVE-2024-24879 on NVD →

Link Library <= 7.5.13 - Cross-Site Request Forgery via action_admin_init

medium

The Link Library plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 7.5.13. This is due to missing or incorrect nonce validation on the action_admin_init() function. This makes it possible for unauthenticated attackers to dismissing a notice via a forged request granted t...

CVSS:
4.3
Affected:
up to 7.5.13
Fixed in:
7.6
Disclosed:
Feb 5, 2024

CVE-2024-24875 on NVD →

Link Library [link-library] < 7.4.1

unknown

[en] The Link Library WordPress plugin before 7.4.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

Affected:
up to 7.4.1
Fixed in:
7.4.1
Disclosed:
Jan 16, 2023

CVE-2022-4199 on NVD →

Link Library <= 7.4 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Link Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's settings in versions up to, and including, 7.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative privileges to inject arbitrary web scripts...

CVSS:
5.5
Affected:
up to 7.4
Fixed in:
7.4.1
Disclosed:
Dec 23, 2022

CVE-2022-4199 on NVD →

Link Library [link-library] < 7.2.9

unknown

[en] The Link Library WordPress plugin before 7.2.8 does not have authorisation in place when deleting links, allowing unauthenticated users to delete arbitrary links via a crafted request

Affected:
up to 7.2.9
Fixed in:
7.2.9
Disclosed:
Feb 1, 2022

CVE-2021-25093 on NVD →

Link Library [link-library] < 7.2.8

unknown

[en] The Link Library WordPress plugin before 7.2.8 does not have CSRF check when resetting library settings, allowing attackers to make a logged in admin reset arbitrary settings via a CSRF attack

Affected:
up to 7.2.8
Fixed in:
7.2.8
Disclosed:
Feb 1, 2022

CVE-2021-25092 on NVD →

Link Library [link-library] < 7.2.9

unknown

[en] The Link Library WordPress plugin before 7.2.9 does not sanitise and escape the settingscopy parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting

Affected:
up to 7.2.9
Fixed in:
7.2.9
Disclosed:
Feb 1, 2022

CVE-2021-25091 on NVD →

Link Library <= 7.2.8 - Reflected Cross-Site Scripting

medium

The Link Library WordPress plugin before 7.2.9 does not sanitise and escape the settingscopy parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting

CVSS:
6.1
Affected:
up to 7.2.8
Fixed in:
7.2.9
Disclosed:
Dec 30, 2021

CVE-2021-25091 on NVD →

Link Library <= 7.2.7 - Missing Authorization Checks

medium

The Link Library WordPress plugin before 7.2.8 does not have authorisation in place when deleting links, allowing unauthenticated users to delete arbitrary links via a crafted request

CVSS:
5.3
Affected:
up to 7.2.7
Fixed in:
7.2.8
Disclosed:
Dec 30, 2021

CVE-2021-25093 on NVD →

Link Library <= 7.2.7 - Cross-Site Request Forgery to Library Settings Reset

medium

The Link Library WordPress plugin before 7.2.8 does not have CSRF check when resetting library settings, allowing attackers to make a logged in admin reset arbitrary settings via a CSRF attack

CVSS:
4.3
Affected:
up to 7.2.7
Fixed in:
7.2.8
Disclosed:
Dec 30, 2021

CVE-2021-25092 on NVD →

Link Library [link-library] < 5.9.13.27

unknown

Authenticated SQL Injection vulnerability found by Lenon Leite in WordPress Link-Library plugin version 5.9.13.26 and earlier versions. Update WordPress Link-Library plugin to the latest available version (at least 5.9.13.27).

Affected:
up to 5.9.13.27
Fixed in:
5.9.13.27
Disclosed:
Aug 16, 2017

Link Library <= 5.9.13.26 – SQL Injection

high

The Link Library plugin for WordPress is vulnerable to generic SQL Injection via the "$_GET[‘linkid’]" parameter in versions up to, and including, 5.9.13.26 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated...

CVSS:
7.2
Affected:
up to 5.9.13.26
Fixed in:
5.9.13.27
Disclosed:
Aug 14, 2017

Link Library [link-library] < 5.9.13.27

unknown

The Link Library plugin for WordPress is vulnerable to generic SQL Injection via the "$_GET[‘linkid’]" parameter in versions up to, and including, 5.9.13.26 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated...

Affected:
up to 5.9.13.27
Fixed in:
5.9.13.27
Disclosed:
Aug 14, 2017

Link Library [link-library] < 5.9.12.30

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.

Affected:
up to 5.9.12.30
Fixed in:
5.9.12.30
Disclosed:
Aug 16, 2016

Link Library <= 5.9.12.29 - Reflected Cross-Site Scripting

medium

The link-library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘'successimportcount’ parameter in versions up to, and including, 5.9.12.29 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pa...

CVSS:
6.1
Affected:
up to 5.9.12.30
Fixed in:
5.9.12.30
Disclosed:
Aug 15, 2016

Link Library [link-library] < 5.9.12.30

unknown

The link-library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘'successimportcount’ parameter in versions up to, and including, 5.9.12.29 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pa...

Affected:
up to 5.9.12.30
Fixed in:
5.9.12.30
Disclosed:
Aug 15, 2016

Link Library [link-library] < 5.1.7

unknown

Because of this vulnerability, remote authenticated users can execute arbitrary SQL commands. Update the plugin.

Affected:
up to 5.1.7
Fixed in:
5.1.7
Disclosed:
May 15, 2015

Link Library [link-library] < 5.0.9

unknown

This plugin is prone to SQL injection in wp-content/plugins/link-library/tracker.php id parameter. Update the plugin.

Affected:
up to 5.0.9
Fixed in:
5.0.9
Disclosed:
May 15, 2015

Link Library [link-library] < 5.0.9

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Vulnerable parameter "id". Update the plugin.

Affected:
up to 5.0.9
Fixed in:
5.0.9
Disclosed:
May 15, 2015

Link Library <= 5.8.10.6 - Reflected Cross-Site Scripting

medium

The Link Library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘searchll’ parameter in versions up to, and including, 5.8.10.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that exe...

CVSS:
6.1
Affected:
up to 5.8.10.6
Fixed in:
5.8.11
Disclosed:
Nov 8, 2014

Link Library [link-library] < 5.8.11

unknown

The Link Library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘searchll’ parameter in versions up to, and including, 5.8.10.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that exe...

Affected:
up to 5.8.11
Fixed in:
5.8.11
Disclosed:
Nov 8, 2014

Link Library [link-library] < 5.2.2

unknown

Link Library plugin is prone to an SQL injection. This vulnerability allows an attacker to modify data, alter queries to the application SQL database, compromise the access and application or exploit hidden vulnerabilities in the underlying database. Upgrade the plugin.

Affected:
up to 5.2.2
Fixed in:
5.2.2
Disclosed:
Sep 24, 2011

Link Library [link-library] < 5.0.9

unknown

The Link Library WordPress plugin was affected by a wp-content/plugins/link-library/tracker.php id Parameter SQL Injection security vulnerability.

Affected:
up to 5.0.9
Fixed in:
5.0.9

Link Library [link-library] < 5.9.13.27

unknown

Type user access: admin user. $_GET[&lsquo;linkid&rsquo;] is not escaped.

Affected:
up to 5.9.13.27
Fixed in:
5.9.13.27

Link Library [link-library] < 5.9.12.30

unknown

The Link Library WordPress plugin was affected by an Authenticated Reflected Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 5.9.12.30
Fixed in:
5.9.12.30

Link Library [link-library] < 5.7.9.7

unknown

The Link Library WordPress plugin was affected by a SQL Injection security vulnerability.

Affected:
up to 5.7.9.7
Fixed in:
5.7.9.7

Link Library [link-library] < 5.1.7

unknown

The Link Library WordPress plugin was affected by a link-library-ajax.php Multiple Parameter SQL Injection security vulnerability.

Affected:
up to 5.1.7
Fixed in:
5.1.7

Link Library [link-library] < 5.0.9

unknown

The Link Library WordPress plugin was affected by a wp-content/plugins/link-library/tracker.php id Parameter XSS security vulnerability.

Affected:
up to 5.0.9
Fixed in:
5.0.9

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database