CVE-2026-78394

CVE-2026-78394 published: The Link Library WordPress plugin before 7.9.6 does not sanitize a user-supplied destination folder before writing a generated image to disk, allowing users with the Contributor role and above to create directories and write or overwrite image files anywher...

View full NVD advisory → ← Back to CVE watch