Link Library <= 7.9.4 - Unauthenticated Arbitrary File Deletion via link_url Parameter
critical
The Link Library plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ll_delete_link_fields function in all versions up to, and including, 7.9.4 This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to...
- CVSS:
- 9.1
- Affected:
- up to 7.9.4
- Fixed in:
- 7.9.5
- Disclosed:
- Aug 14, 2026
CVE-2026-18855 on NVD →
Link Library <= 7.9.3 - Reflected Cross-Site Scripting
medium
The Link Library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 7.9.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully tr...
- CVSS:
- 6.1
- Affected:
- up to 7.9.3
- Fixed in:
- 7.9.4
- Disclosed:
- Aug 3, 2026
CVE-2026-16535 on NVD →
Link Library < 7.9.4 - Reflected Cross-Site Scripting
medium
The Link Library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to 7.9.4 (exclusive) due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully tr...
- CVSS:
- 6.1
- Affected:
- up to 7.9.4
- Fixed in:
- 7.9.4
- Disclosed:
- Jul 29, 2026
CVE-2026-18197 on NVD →
Link Library <= 7.9.2 - Unauthenticated SQL Injection
high
The Link Library plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 7.9.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries int...
- CVSS:
- 7.5
- Affected:
- up to 7.9.2
- Fixed in:
- 7.9.3
- Disclosed:
- Jul 23, 2026
CVE-2026-16532 on NVD →
Link Library <= 7.8.8 - Authenticated (Contributor+) Arbitrary File Deletion
high
The Link Library plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all versions up to, and including, 7.8.8. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete arbitrary files on the server, which can easily lead...
- CVSS:
- 8.1
- Affected:
- up to 7.8.8
- Fixed in:
- 7.8.9
- Disclosed:
- Apr 22, 2026
CVE-2026-40779 on NVD →
Link Library <= 7.8.7 - Authenticated (Contributor+) Server-Side Request Forgery
medium
The Link Library plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.8.7. This makes it possible for authenticated attackers, with Contributor-level access and above, to make web requests to arbitrary locations originating from the web application which can be used...
- CVSS:
- 6.4
- Affected:
- up to 7.8.7
- Fixed in:
- 7.8.8
- Disclosed:
- Dec 24, 2025
CVE-2025-68600 on NVD →
Link Library [link-library] <= 7.8.4 (unfixed)
unknown
[en] Server-Side Request Forgery (SSRF) vulnerability in Yannick Lefebvre Link Library link-library allows Server Side Request Forgery.This issue affects Link Library: from n/a through <= 7.8.4.
- Affected:
- up to 7.8.4
- Fix:
- No patched version reported
- Disclosed:
- Dec 24, 2025
CVE-2025-68600 on NVD →
Link Library <= 7.8 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Link Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that...
- CVSS:
- 6.4
- Affected:
- up to 7.8
- Fixed in:
- 7.8.1
- Disclosed:
- Apr 22, 2025
CVE-2025-46237 on NVD →
Link Library [link-library] < 7.8.1
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yannick Lefebvre Link Library allows Stored XSS. This issue affects Link Library: from n/a through 7.8.
- Affected:
- up to 7.8.1
- Fixed in:
- 7.8.1
- Disclosed:
- Apr 22, 2025
CVE-2025-46237 on NVD →
Link Library <= 7.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Link Additional Parameters
medium
The Link Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Link Additional Parameters in all versions up to, and including, 7.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to in...
- CVSS:
- 6.4
- Affected:
- up to 7.7.3
- Fixed in:
- 7.8
- Disclosed:
- Apr 4, 2025
CVE-2025-2889 on NVD →
Link Library [link-library] < 7.7.3
unknown
[en] The Link Library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'searchll' parameter in all versions up to, and including, 7.7.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages th...
- Affected:
- up to 7.7.3
- Fixed in:
- 7.7.3
- Disclosed:
- Jan 21, 2025
CVE-2024-13404 on NVD →
Link Library <= 7.7.2 - Reflected Cross-Site Scripting
medium
The Link Library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'searchll' parameter in all versions up to, and including, 7.7.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that ex...
- CVSS:
- 6.1
- Affected:
- up to 7.7.2
- Fixed in:
- 7.7.3
- Disclosed:
- Jan 20, 2025
CVE-2024-13404 on NVD →
Link Library [link-library] < 7.7.2
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Yannick Lefebvre Link Library allows Reflected XSS.This issue affects Link Library: from n/a through 7.7.1.
- Affected:
- up to 7.7.2
- Fixed in:
- 7.7.2
- Disclosed:
- Jul 20, 2024
CVE-2024-38711 on NVD →
Link Library <= 7.7.1 - Reflected Cross-Site Scripting
medium
The Link Library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 7.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully tr...
- CVSS:
- 6.1
- Affected:
- up to 7.7.1
- Fixed in:
- 7.7.2
- Disclosed:
- Jul 11, 2024
CVE-2024-38711 on NVD →
Link Library [link-library] < 7.6.4
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Yannick Lefebvre Link Library link-library allows Reflected XSS.This issue affects Link Library: from n/a through 7.6.3.
- Affected:
- up to 7.6.4
- Fixed in:
- 7.6.4
- Disclosed:
- Jun 8, 2024
CVE-2024-35687 on NVD →
Link Library <= 7.6.3 - Reflected Cross-Site Scripting
medium
The Link Library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 7.6.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfull...
- CVSS:
- 6.1
- Affected:
- up to 7.6.3
- Fixed in:
- 7.6.4
- Disclosed:
- Jun 6, 2024
CVE-2024-35687 on NVD →
Link Library [link-library] < 7.7
unknown
[en] The Link Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'link-library' shortcode in all versions up to, and including, 7.6.11 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with...
- Affected:
- up to 7.7
- Fixed in:
- 7.7
- Disclosed:
- May 8, 2024
CVE-2024-4281 on NVD →
Link Library <= 7.6.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via link-library Shortcode
medium
The Link Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'link-library' shortcode in all versions up to, and including, 7.6.11 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contr...
- CVSS:
- 6.4
- Affected:
- up to 7.6.11
- Fixed in:
- 7.7
- Disclosed:
- May 7, 2024
CVE-2024-4281 on NVD →
Link Library [link-library] < 7.6.7
unknown
[en] The Link Library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the searchll parameter in all versions up to, and including, 7.6.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that...
- Affected:
- up to 7.6.7
- Fixed in:
- 7.6.7
- Disclosed:
- Apr 9, 2024
CVE-2024-2325 on NVD →
Link Library [link-library] < 7.6.1
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yannick Lefebvre Link Library allows Reflected XSS.This issue affects Link Library: from n/a through 7.6.
- Affected:
- up to 7.6.1
- Fixed in:
- 7.6.1
- Disclosed:
- Mar 19, 2024
CVE-2024-29123 on NVD →
Link Library <= 7.6 - Reflected Cross-Site Scripting
medium
The Link Library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 7.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully tric...
- CVSS:
- 6.1
- Affected:
- up to 7.6
- Fixed in:
- 7.6.1
- Disclosed:
- Mar 16, 2024
CVE-2024-29123 on NVD →
Link Library <= 7.6.6 - Reflected Cross-Site Scripting
medium
The Link Library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the searchll parameter in all versions up to, and including, 7.6.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that exec...
- CVSS:
- 6.1
- Affected:
- up to 7.6.6
- Fixed in:
- 7.6.7
- Disclosed:
- Mar 13, 2024
CVE-2024-2325 on NVD →
Link Library [link-library] < 7.6.1
unknown
[en] The Link Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'll_reciprocal' parameter in all versions up to, and including, 7.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages th...
- Affected:
- up to 7.6.1
- Fixed in:
- 7.6.1
- Disclosed:
- Feb 20, 2024
CVE-2024-1559 on NVD →
Link Library <= 7.6 - Unauthenticated Stored Cross-Site Scripting
medium
The Link Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'll_reciprocal' parameter in all versions up to, and including, 7.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that wi...
- CVSS:
- 6.5
- Affected:
- up to 7.6
- Fixed in:
- 7.6.1
- Disclosed:
- Feb 19, 2024
CVE-2024-1559 on NVD →
Link Library [link-library] < 7.6
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Yannick Lefebvre Link Library.This issue affects Link Library: from n/a through 7.5.13.
- Affected:
- up to 7.6
- Fixed in:
- 7.6
- Disclosed:
- Feb 12, 2024
CVE-2024-24875 on NVD →
Link Library [link-library] < 7.6
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yannick Lefebvre Link Library allows Reflected XSS.This issue affects Link Library: from n/a through 7.5.13.
- Affected:
- up to 7.6
- Fixed in:
- 7.6
- Disclosed:
- Feb 8, 2024
CVE-2024-24879 on NVD →
Link Library <= 7.5.13 - Reflected Cross-Site Scripting via 'link_price' and 'link_tags'
medium
The Link Library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'link_price' and 'link_tags' parameters in versions up to, and including, 7.5.13 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts...
- CVSS:
- 6.1
- Affected:
- up to 7.5.13
- Fixed in:
- 7.6
- Disclosed:
- Feb 5, 2024
CVE-2024-24879 on NVD →
Link Library <= 7.5.13 - Cross-Site Request Forgery via action_admin_init
medium
The Link Library plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 7.5.13. This is due to missing or incorrect nonce validation on the action_admin_init() function. This makes it possible for unauthenticated attackers to dismissing a notice via a forged request granted t...
- CVSS:
- 4.3
- Affected:
- up to 7.5.13
- Fixed in:
- 7.6
- Disclosed:
- Feb 5, 2024
CVE-2024-24875 on NVD →
Link Library [link-library] < 7.4.1
unknown
[en] The Link Library WordPress plugin before 7.4.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
- Affected:
- up to 7.4.1
- Fixed in:
- 7.4.1
- Disclosed:
- Jan 16, 2023
CVE-2022-4199 on NVD →
Link Library <= 7.4 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Link Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's settings in versions up to, and including, 7.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative privileges to inject arbitrary web scripts...
- CVSS:
- 5.5
- Affected:
- up to 7.4
- Fixed in:
- 7.4.1
- Disclosed:
- Dec 23, 2022
CVE-2022-4199 on NVD →
Link Library [link-library] < 7.2.9
unknown
[en] The Link Library WordPress plugin before 7.2.8 does not have authorisation in place when deleting links, allowing unauthenticated users to delete arbitrary links via a crafted request
- Affected:
- up to 7.2.9
- Fixed in:
- 7.2.9
- Disclosed:
- Feb 1, 2022
CVE-2021-25093 on NVD →
Link Library [link-library] < 7.2.8
unknown
[en] The Link Library WordPress plugin before 7.2.8 does not have CSRF check when resetting library settings, allowing attackers to make a logged in admin reset arbitrary settings via a CSRF attack
- Affected:
- up to 7.2.8
- Fixed in:
- 7.2.8
- Disclosed:
- Feb 1, 2022
CVE-2021-25092 on NVD →
Link Library [link-library] < 7.2.9
unknown
[en] The Link Library WordPress plugin before 7.2.9 does not sanitise and escape the settingscopy parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting
- Affected:
- up to 7.2.9
- Fixed in:
- 7.2.9
- Disclosed:
- Feb 1, 2022
CVE-2021-25091 on NVD →
Link Library <= 7.2.8 - Reflected Cross-Site Scripting
medium
The Link Library WordPress plugin before 7.2.9 does not sanitise and escape the settingscopy parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting
- CVSS:
- 6.1
- Affected:
- up to 7.2.8
- Fixed in:
- 7.2.9
- Disclosed:
- Dec 30, 2021
CVE-2021-25091 on NVD →
Link Library <= 7.2.7 - Missing Authorization Checks
medium
The Link Library WordPress plugin before 7.2.8 does not have authorisation in place when deleting links, allowing unauthenticated users to delete arbitrary links via a crafted request
- CVSS:
- 5.3
- Affected:
- up to 7.2.7
- Fixed in:
- 7.2.8
- Disclosed:
- Dec 30, 2021
CVE-2021-25093 on NVD →
Link Library <= 7.2.7 - Cross-Site Request Forgery to Library Settings Reset
medium
The Link Library WordPress plugin before 7.2.8 does not have CSRF check when resetting library settings, allowing attackers to make a logged in admin reset arbitrary settings via a CSRF attack
- CVSS:
- 4.3
- Affected:
- up to 7.2.7
- Fixed in:
- 7.2.8
- Disclosed:
- Dec 30, 2021
CVE-2021-25092 on NVD →
Link Library [link-library] < 5.9.13.27
unknown
Authenticated SQL Injection vulnerability found by Lenon Leite in WordPress Link-Library plugin version 5.9.13.26 and earlier versions.
Update WordPress Link-Library plugin to the latest available version (at least 5.9.13.27).
- Affected:
- up to 5.9.13.27
- Fixed in:
- 5.9.13.27
- Disclosed:
- Aug 16, 2017
Link Library <= 5.9.13.26 – SQL Injection
high
The Link Library plugin for WordPress is vulnerable to generic SQL Injection via the "$_GET[‘linkid’]" parameter in versions up to, and including, 5.9.13.26 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated...
- CVSS:
- 7.2
- Affected:
- up to 5.9.13.26
- Fixed in:
- 5.9.13.27
- Disclosed:
- Aug 14, 2017
Link Library [link-library] < 5.9.13.27
unknown
The Link Library plugin for WordPress is vulnerable to generic SQL Injection via the "$_GET[‘linkid’]" parameter in versions up to, and including, 5.9.13.26 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated...
- Affected:
- up to 5.9.13.27
- Fixed in:
- 5.9.13.27
- Disclosed:
- Aug 14, 2017
Link Library [link-library] < 5.9.12.30
unknown
Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.
Update the plugin.
- Affected:
- up to 5.9.12.30
- Fixed in:
- 5.9.12.30
- Disclosed:
- Aug 16, 2016
Link Library <= 5.9.12.29 - Reflected Cross-Site Scripting
medium
The link-library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘'successimportcount’ parameter in versions up to, and including, 5.9.12.29 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pa...
- CVSS:
- 6.1
- Affected:
- up to 5.9.12.30
- Fixed in:
- 5.9.12.30
- Disclosed:
- Aug 15, 2016
Link Library [link-library] < 5.9.12.30
unknown
The link-library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘'successimportcount’ parameter in versions up to, and including, 5.9.12.29 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pa...
- Affected:
- up to 5.9.12.30
- Fixed in:
- 5.9.12.30
- Disclosed:
- Aug 15, 2016
Link Library [link-library] < 5.1.7
unknown
Because of this vulnerability, remote authenticated users can execute arbitrary SQL commands.
Update the plugin.
- Affected:
- up to 5.1.7
- Fixed in:
- 5.1.7
- Disclosed:
- May 15, 2015
Link Library [link-library] < 5.0.9
unknown
This plugin is prone to SQL injection in wp-content/plugins/link-library/tracker.php id parameter.
Update the plugin.
- Affected:
- up to 5.0.9
- Fixed in:
- 5.0.9
- Disclosed:
- May 15, 2015
Link Library [link-library] < 5.0.9
unknown
Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Vulnerable parameter "id".
Update the plugin.
- Affected:
- up to 5.0.9
- Fixed in:
- 5.0.9
- Disclosed:
- May 15, 2015
Link Library <= 5.8.10.6 - Reflected Cross-Site Scripting
medium
The Link Library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘searchll’ parameter in versions up to, and including, 5.8.10.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that exe...
- CVSS:
- 6.1
- Affected:
- up to 5.8.10.6
- Fixed in:
- 5.8.11
- Disclosed:
- Nov 8, 2014
Link Library [link-library] < 5.8.11
unknown
The Link Library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘searchll’ parameter in versions up to, and including, 5.8.10.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that exe...
- Affected:
- up to 5.8.11
- Fixed in:
- 5.8.11
- Disclosed:
- Nov 8, 2014
Link Library [link-library] < 5.2.2
unknown
Link Library plugin is prone to an SQL injection. This vulnerability allows an attacker to modify data, alter queries to the application SQL database, compromise the access and application or exploit hidden vulnerabilities in the underlying database.
Upgrade the plugin.
- Affected:
- up to 5.2.2
- Fixed in:
- 5.2.2
- Disclosed:
- Sep 24, 2011
Link Library [link-library] < 7.8
unknown
- Affected:
- up to 7.8
- Fixed in:
- 7.8
CVE-2025-2889 on NVD →
Link Library [link-library] < 5.0.9
unknown
The Link Library WordPress plugin was affected by a wp-content/plugins/link-library/tracker.php id Parameter SQL Injection security vulnerability.
- Affected:
- up to 5.0.9
- Fixed in:
- 5.0.9
Link Library [link-library] < 5.9.13.27
unknown
Type user access: admin user.
$_GET[‘linkid’] is not escaped.
- Affected:
- up to 5.9.13.27
- Fixed in:
- 5.9.13.27
Link Library [link-library] < 5.9.12.30
unknown
The Link Library WordPress plugin was affected by an Authenticated Reflected Cross-Site Scripting (XSS) security vulnerability.
- Affected:
- up to 5.9.12.30
- Fixed in:
- 5.9.12.30
Link Library [link-library] < 5.7.9.7
unknown
The Link Library WordPress plugin was affected by a SQL Injection security vulnerability.
- Affected:
- up to 5.7.9.7
- Fixed in:
- 5.7.9.7
Link Library [link-library] < 5.1.7
unknown
The Link Library WordPress plugin was affected by a link-library-ajax.php Multiple Parameter SQL Injection security vulnerability.
- Affected:
- up to 5.1.7
- Fixed in:
- 5.1.7
Link Library [link-library] < 5.0.9
unknown
The Link Library WordPress plugin was affected by a wp-content/plugins/link-library/tracker.php id Parameter XSS security vulnerability.
- Affected:
- up to 5.0.9
- Fixed in:
- 5.0.9