在 WordPress 的 Link Library 插件 7.9.6 版本之前,该插件在将生成的图像写入磁盘之前,未对用户提供的目标文件夹路径进行清理(sanitization)。这一漏洞允许具备“Contributor”角色及以上权限的用户创建目录,并在 Web 服务器具有写入权限的任何位置(包括站点文档根目录之外)写入或覆盖图像文件。 由于写入的文件名始终为纯数字并带有固定的图像扩展名,因此攻击者无法通过此方式植入可执行代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Link Library | 0 ~ 7.9.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-80514 | 5.3 MEDIUM | wpForo Forum 3.0.0 - 3.1.5 - Unauthenticated AI Credit Exhaustion via IP Rate Limit Bypass |
| CVE-2026-86837 | 5.3 MEDIUM | Bookly < 28.3 - Unauthenticated Customer PII Update via Verification Bypass |
| CVE-2026-88848 | 4.2 MEDIUM | MasterStudy LMS 1.9 - < 3.7.50 - Subscriber+ Membership Plan Quota and Category Restrictio |
| CVE-2026-78397 | Link Library < 7.9.6 - Unauthenticated SSRF via Reciprocal Link Validation | |
| CVE-2026-78393 | Link Library < 7.9.6 - Reflected XSS via 'link_tags' and 'link_price' Sort and Breadcrumb |
No comments yet