---
id: CVE-2026-78394
title: >-
  The Link Library WordPress plugin before 7.9.6 does not sanitize a
  user-supplied destination folder before writing a generated image to disk,
  allowing users with the Contributor role and above to create directories and
  write or overwrite…
summary: >-
  The Link Library WordPress plugin before 7.9.6 does not sanitize a
  user-supplied destination folder before writing a generated image to disk,
  allowing users with the Contributor role and above to create directories and
  write or overwrite…
severity: medium
cvss: 4.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:N'
cwe:
  - CWE-22
product: Link Library
affected:
  - link_library < 7.9.6
published: '2026-09-25'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T13:25:48.533'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-78394'
references:
  - url: 'https://wpscan.com/vulnerability/9da07b4f-5332-4ba5-8a34-6f2ed303b62c/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-25T12:37:04.268157Z'
ingestedAt: '2026-09-25T07:01:12.115Z'
---

## Overview

The Link Library WordPress plugin before 7.9.6 does not sanitize a user-supplied destination folder before writing a generated image to disk, allowing users with the Contributor role and above to create directories and write or overwrite image files anywhere the web server can write, including outside the site's document root.

The written file name is always numeric with a fixed image extension, so executable code cannot be planted this way.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
