Impact
The Visual Link Preview plugin for WordPress is vulnerable to stored cross‑site scripting because the shortcode attributes are not properly sanitized or escaped. An authenticated attacker with contributor‑level access can embed arbitrary JavaScript into the attribute values, resulting in script execution whenever a page containing the malicious shortcode is viewed by any user.
Affected Systems
WordPress sites using the Visual Link Preview plugin developed by BrechtVds, specifically versions up to and including 2.2.7, are affected. Sites that have enabled the visual‑link‑preview shortcode and grant contributor or higher permissions to content editors are at risk.
Risk and Exploitability
With a CVSS score of 6.4 the vulnerability presents moderate severity and an EPSS score of less than 1% indicates a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Successful exploitation requires a user authenticated with contributor or higher, allowing the injection of malicious scripts that will run in the browsers of any visitor who loads the affected page.
OpenCVE Enrichment