CVE-2026-78394
Last modified
CVE-2026-78394 is a medium-severity vulnerability rated 4.1/10 on the CVSS scale. The Link Library WordPress plugin before 7.9.6 does not sanitize a user-supplied destination folder before writing a generated image to disk, allowing users with the Contributor role and above to create directories and write or overwrite image files anywhere the web server can write, including outside the site's document root. The written file name is always numeric with a fixed image extension, so executable code cannot be planted this way..
Description
The Link Library WordPress plugin before 7.9.6 does not sanitize a user-supplied destination folder before writing a generated image to disk, allowing users with the Contributor role and above to create directories and write or overwrite image files anywhere the web server can write, including outside the site's document root. The written file name is always numeric with a fixed image extension, so executable code cannot be planted this way.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Unknown | Link Library | < 7.9.6 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-78394?
How severe is CVE-2026-78394?
How do I fix CVE-2026-78394?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-78385RansomLook contains insufficient resource validation in the …8.2
- CVE-2026-78386RansomLook exposed sensitive operator-side scraping configur…8.7
- CVE-2026-78387RansomLook contains an authorization weakness in the web-bas…9.4
- CVE-2026-7839UltraVNC repeater through 1.8.2.2 initializes the HTTP admin…9.1
- CVE-2026-78391RansomLook contains a stored cross-site scripting (XSS) vuln…8.8
- CVE-2026-78393The Link Library WordPress plugin before 7.9.6 does not prop…6.1
- CVE-2026-78397The Link Library WordPress plugin before 7.9.6 does not vali…4
- CVE-2026-7840UltraVNC repeater through 1.8.2.2 contains a global buffer o…9.8
- CVE-2026-78408The nsenter --join-cgroup option opens the target cgroup.pro…7.9
- CVE-2026-78409The X-mount.subdir option uses a detached-tree fast path on …7
- CVE-2026-7841A remote code execution vulnerability exists in Notification…8.8
- CVE-2026-78410A flaw was found in util-linux. Restricted bind mounts take …7.8
Are you affected by CVE-2026-78394?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
