CVE-2026-16532 PUBLISHED

Link Library < 7.9.3 - Unauthenticated SQL Injection via the Front-End Link Submission Form

Assigner: WPScan
Reserved: 22.07.2026 Published: 03.08.2026 Updated: 03.08.2026

The Link Library WordPress plugin before 7.9.3 does not properly sanitise and escape a user-supplied value before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.

Product Status

Vendor Unknown
Product Link Library
Versions Default: unaffected
  • affected from 0 to 7.9.3 (excl.)

Credits

  • Abdullah Kareem (cyberkareem) finder
  • WPScan coordinator

References

Problem Types

  • CWE-89 SQL Injection CWE