CVE-2026-78394: Link Library < 7.9.6 - Contributor+ Path Traversal via 'filepath' Parameter

Published Sep 25, 2026
·
Updated

The Link Library WordPress plugin before 7.9.6 does not sanitize a user-supplied destination folder before writing a generated image to disk, allowing users with the Contributor role and above to create directories and write or overwrite image files anywhere the web server can write, including outside the site's document root.

The written file name is always numeric with a fixed image extension, so executable code cannot be planted this way.

Affected Software

1 affected component
Link Library Link Library<7.9.6

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Link Library WordPress plugin to a version that resolves this vulnerability.

    Fixed in 7.9.6

Event History

Sep 25, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·07:16 AM
Description

Frequently Asked Questions

1

Who can exploit this issue?

An authenticated WordPress user with the Contributor role or any higher-privileged role can exploit it. Unauthenticated visitors are not described as able to trigger the vulnerable behavior.

2

What access does an attacker need to write files outside the site directory?

The attacker needs a Contributor-or-higher account and must be able to supply the destination folder through the filepath parameter. The resulting writes are limited to locations writable by the web server.

3

Can this vulnerability be used to upload a PHP shell or other executable code?

The generated filename is numeric and uses a fixed image extension, so the issue cannot directly plant executable code. It can still create directories and write or overwrite image files, including outside the document root where the web server has write permission.

4

Which versions are affected?

Link Library versions before 7.9.6 are affected. Updating to version 7.9.6 or later addresses the described unsanitized destination-folder handling.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203