Junglewise Threat Intelligence

CVE-2026-39670: Brecht Visual Link Preview SSRF in WordPress plugin

CVE-2026-39670 · Severity: medium · CVSS 6 · Published 2026-04-08

Technologies: Brecht Visual Link Preview.

Executive brief

The Visual Link Preview plugin for WordPress, which allows users to create aesthetic previews of external links, is vulnerable to Server-Side Request Forgery (SSRF). An attacker with basic contributor-level access can force the website's server to make unauthorized requests to internal or external systems. This could lead to the exposure of sensitive information from internal services that are not normally accessible from the internet.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the Brecht Visual Link Preview plugin for WordPress (versions <= 2.3.0). The flaw is located in the link preview generation logic, which fails to properly validate user-supplied URLs before the server initiates a request to them. An attacker with 'Contributor' or higher privileges can exploit this to scan internal networks, bypass firewalls, or interact with internal services running on the host. The vulnerability is mitigated by a high attack complexity (AC:H) requirement, likely due to specific configuration or environmental factors needed for successful exploitation. A patch is available in version 2.3.1.

Affected products

  • Brecht Visual Link Preview <= 2.3.0

Timeline

  • 2026-01-20: other: Vulnerability reported by Nguyen Ba Khanh
  • 2026-02-19: patched: Version 2.3.1 released to address the issue
  • 2026-04-08: disclosed: CVE published

References