PatchSiren cyber security CVE debrief
CVE-2026-39670 Brecht CVE debrief
A Server-Side Request Forgery (SSRF) vulnerability was discovered in the Visual Link Preview plugin for WordPress. The issue, tracked as CVE-2026-39670, allows attackers to make unauthorized requests on behalf of the server. The vulnerability affects the plugin from its inception up to and including version 2.3.0. Users of the affected versions should consider updating to a patched version, if available, to mitigate potential risks.
- Vendor
- Brecht
- Product
- Visual Link Preview
- CVSS
- MEDIUM 6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-08
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-08
- Advisory updated
- 2026-07-24
Who should care
Administrators and users of the Visual Link Preview plugin for WordPress should be aware of this vulnerability, especially if they have not updated to a version beyond 2.3.0. Given the medium severity of the vulnerability, caution is advised, particularly in environments where SSRF could lead to significant impacts.
Technical summary
CVE-2026-39670 is a Server-Side Request Forgery (SSRF) vulnerability in the Visual Link Preview plugin for WordPress. This vulnerability, with a CVSS score of 6 (Medium severity), allows an attacker to forge requests from the server, potentially leading to unauthorized access or data breaches. The vulnerability exists from the plugin's inception through version 2.3.0. The CVSS vector for this vulnerability is CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L, indicating that the attack vector is network-based, requires high complexity, low privileges, no user interaction, and can affect confidentiality, integrity, and availability.
Defensive priority
Medium priority should be given to addressing CVE-2026-39670 due to its potential impact. Although the CVSS score is medium, the nature of SSRF vulnerabilities can lead to significant risks, including unauthorized access and data leakage. Therefore, it is recommended to update the Visual Link Preview plugin to a version that mitigates this vulnerability.
Recommended defensive actions
- Update the Visual Link Preview plugin to a version beyond 2.3.0, if available.
- Review server configurations and network access controls to mitigate potential impacts of SSRF.
- Monitor for suspicious activity that could indicate exploitation attempts.
Evidence notes
The CVE record for CVE-2026-39670 was published on 2026-04-08T09:16:38.423Z and last modified on 2026-07-24T20:10:00.147Z. The NVD entry for this CVE is currently Deferred. Information about the vulnerability was obtained from Patchstack, indicating a Server-Side Request Forgery (SSRF) vulnerability in the Visual Link Preview plugin.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-39670 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-39670
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-39670 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-39670
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.