Impact
The Visual Link Preview plugin, versions 2.3.1 and earlier, contains a sensitive data exposure flaw that allows an attacker to retrieve private subscriber information. The flaw is categorized as CWE-201, indicating that the application does not adequately protect against the disclosure of confidential data. If exploited, an attacker could view or download subscriber data that should remain confidential, thereby compromising user privacy and potentially leading to further attacks such as phishing or credential stuffing.
Affected Systems
WordPress sites running the Visual Link Preview plugin from Bootstrapped Ventures, specifically any installation on or before version 2.3.1. The vendor recommends upgrading to the latest available version, 2.4.0 or newer, which contains the fix for this vulnerability.
Risk and Exploitability
The CVSS score of 7.4 indicates high severity and the lack of an EPSS score means no publicly documented exploitation probability is available. The vulnerability is not listed in the CISA KEV catalog, suggesting it has not been widely exploited yet. The likely attack vector is remote, where a malicious actor could manipulate plugin requests or view exposed data through the plugin’s interface or REST endpoints. Defensive measures should therefore focus on removing or patching the plugin as soon as possible to eliminate the data exposure risk.
OpenCVE Enrichment