WordPress Plugin Vulnerabilities

Link Library < 7.9.6 - Contributor+ Path Traversal via 'filepath' Parameter

Description

The plugin does not sanitize a user-supplied destination folder before writing a generated image to disk, allowing users with the Contributor role and above to create directories and write or overwrite image files anywhere the web server can write, including outside the site's document root.

The written file name is always numeric with a fixed image extension, so executable code cannot be planted this way.

Proof of Concept

Affects Plugins

Fixed in 7.9.6

References

Classification

Type
TRAVERSAL
OWASP top 10
CWE

Miscellaneous

Original Researcher
Karthik Ramakrishnan
Submitter
Karthik Ramakrishnan
Verified
Yes

Timeline

Publicly Published
2026-09-23 (about 2 days ago)
Added
2026-09-23 (about 1 day ago)
Last Updated
2026-09-23 (about 1 day ago)

Other