Executive brief
The Visual Link Preview plugin for WordPress, which allows users to create custom preview boxes for links, contains a security flaw that exposes sensitive information. An attacker with a basic 'Subscriber' account can access data that should normally be restricted to administrators. This exposure could reveal system details or other internal information that helps an attacker launch more advanced attacks against the website.
Technical details
A sensitive data exposure vulnerability exists in the Visual Link Preview plugin for WordPress (versions up to and including 2.4.1). The flaw is classified as CWE-497 (Exposure of Sensitive System Information to an Unauthorized Control Sphere). It allows an authenticated attacker with Subscriber-level privileges to access sensitive information that is not intended for their role. The vulnerability is reachable over the network without user interaction. A patch is available in version 2.4.2, which addresses the improper access control or information leakage.
Affected products
- Bootstrapped Ventures Visual Link Preview <= 2.4.1
Timeline
- 2026-05-14: other: Reported by Aliefis
- 2026-06-02: patched: Version 2.4.2 released
- 2026-06-15: disclosed: NVD publication date