Link Library <= 7.8.8 - Authenticated (Contributor+) Arbitrary File Deletion
Link Library
Minimum safe version
7.8.9
Update to 7.8.9 or later to address 32 fixable vulnerabilities
CVE-2025-68600
CVE-2025-46237
Link Library <= 7.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Link Additional Parameters
CVE-2024-13404
CVE-2024-38711
CVE-2024-35687
CVE-2024-4281
CVE-2024-29123
CVE-2024-2325
CVE-2024-1559
CVE-2024-24875
CVE-2024-24879
Link Library 5.1.6 - link-library-ajax.php Multiple Parameter SQL Injection
Link Library 5.0.8 - wp-content/plugins/link-library/tracker.php id Parameter XSS
Link Library 5.0.8 - wp-content/plugins/link-library/tracker.php id Parameter SQL Injection
Link Library <= 5.2.1 - SQL Injection
Link Library <= 5.9.12.29 - Authenticated Reflected Cross-Site Scripting (XSS)
Link-Library <= 5.9.13.26 – Authenticated SQL Injection
WordPress Link Library Plugin < 7.4.1 is vulnerable to Cross Site Scripting (XSS)
Link Library <= 5.8.10.6 - Reflected Cross-Site Scripting
Link Library <= 5.9.12.29 - Reflected Cross-Site Scripting
Link Library <= 5.9.13.26 – SQL Injection
WordPress Link Library Plugin <= 5.2.1 - SQL Injection
WordPress Link Library Plugin <= 5.0.8 - SQL Injection
WordPress Link Library Plugin <= 5.0.8 - Cross Site Scripting
WordPress Link Library Plugin <= 5.1.6 - SQL Injection
WordPress Link Library Plugin <= 5.9.12.29 - Cross Site Scripting
WordPress Link-Library plugin <=5.9.13.26 – Authenticated SQL Injection vulnerability
CVE-2021-25093
CVE-2021-25092
CVE-2021-25091