Impact
Missing authorization in the Visual Link Preview plugin allows an attacker to perform actions meant for privileged users. By bypassing access checks, an attacker can manipulate plugin functionality or access sensitive data. This weakness aligns with CWE‑862 (Missing Authorization) and can result in unauthorized changes or data exposure.
Affected Systems
The issue affects the Visual Link Preview plugin by Brecht, available for WordPress installations. Versions from the initial release up through 2.2.9 are impacted. Any WordPress site that has this plugin installed and has not upgraded beyond 2.2.9 is potentially vulnerable.
Risk and Exploitability
With a CVSS score of 6.5, the vulnerability presents a high impact to confidentiality, integrity, and availability. The EPSS score is below 1%, indicating a low likelihood of active exploitation at the time of this assessment. The plugin can be accessed over the web, so the attack vector is likely unauthenticated HTTP requests to plugin endpoints. Although no public exploit code is known, the combination of global availability and lack of authorization makes the risk significant for sites that cannot immediately patch.
OpenCVE Enrichment