CVE-2026-78397: Link Library < 7.9.6 - Unauthenticated SSRF via Reciprocal Link Validation

Published Sep 25, 2026
·
Updated

The Link Library WordPress plugin before 7.9.6 does not validate the destination of a user-supplied URL before falling back to an unprotected fetch when its safe request is rejected, allowing unauthenticated visitors to make the site issue requests to hosts on its internal network and to learn from the response whether an internal service answered.

Versions below 7.8.8 are covered by CVE-2025-68600; this entry covers 7.8.8 through 7.9.5, where that fix was incomplete. Exploitation requires the site owner to have published the Link Library WordPress plugin before 7.9.6's public link submission form with reciprocal-link validation enabled.

Affected Software

1 affected component
Link Library Link Library WordPress plugin>=7.8.8<=7.9.5

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Link Library WordPress plugin to a version that resolves this vulnerability.

    Fixed in 7.9.6

Event History

Sep 25, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·07:16 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which sites are exposed to this issue?

Sites using Link Library versions 7.8.8 through 7.9.5 are exposed only if the owner has published the plugin's public link submission form and enabled reciprocal-link validation. The issue can be exploited by unauthenticated visitors in that configuration.

2

What can an attacker do with successful exploitation?

An attacker can cause the WordPress site to send requests to hosts on its internal network. They can also learn from the response whether an internal service answered.

3

What should be prioritized for mitigation?

Update Link Library to version 7.9.6 or later. If updating cannot happen immediately, remove public access to the link submission form or disable reciprocal-link validation, since both are required for exploitation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203