A vulnerability categorized as problematic has been discovered in jackdewey Link Library Plugin up to 7.9.4 on WordPress. The affected element is the function
ll_delete_link_fields. The manipulation results in path traversal.
This vulnerability is identified as CVE-2026-18855. The attack can be executed remotely. There is not any exploit available.