Executive brief
The Visual Link Preview plugin for WordPress, which allows users to create aesthetic previews for internal and external links, contains a security flaw that exposes sensitive information. An attacker with a basic 'Subscriber' account could gain access to data that should normally be restricted to administrators. This exposure could be used to gather intelligence for further attacks or compromise the privacy of the site's operations.
Technical details
The Visual Link Preview plugin (versions 2.3.1 and below) for WordPress suffers from an insertion of sensitive information into sent data (CWE-201). The vulnerability allows an authenticated user with low-level 'Subscriber' privileges to access sensitive information that is not intended for their role. The flaw is categorized as a sensitive data exposure issue within the plugin's data handling logic. An attacker can exploit this over the network without user interaction to retrieve restricted data, potentially facilitating further system compromise. The issue is resolved in version 2.4.0.
Affected products
- Bootstrapped Ventures Visual Link Preview <= 2.3.1
Timeline
- 2026-04-24: other: Vulnerability reported by researcher she11f
- 2026-06-17: advisory: Patchstack advisory published
- 2026-06-25: disclosed: NVD publication date
- 2026-06-25: patched: Version 2.4.0 released to address the vulnerability