PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-39670 Brecht CVE debrief

A Server-Side Request Forgery (SSRF) vulnerability was discovered in the Visual Link Preview plugin for WordPress. The issue, tracked as CVE-2026-39670, allows attackers to make unauthorized requests on behalf of the server. The vulnerability affects the plugin from its inception up to and including version 2.3.0. Users of the affected versions should consider updating to a patched version, if available, to mitigate potential risks.

Vendor
Brecht
Product
Visual Link Preview
CVSS
MEDIUM 6
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-08
Original CVE updated
2026-07-24
Advisory published
2026-04-08
Advisory updated
2026-07-24

Who should care

Administrators and users of the Visual Link Preview plugin for WordPress should be aware of this vulnerability, especially if they have not updated to a version beyond 2.3.0. Given the medium severity of the vulnerability, caution is advised, particularly in environments where SSRF could lead to significant impacts.

Technical summary

CVE-2026-39670 is a Server-Side Request Forgery (SSRF) vulnerability in the Visual Link Preview plugin for WordPress. This vulnerability, with a CVSS score of 6 (Medium severity), allows an attacker to forge requests from the server, potentially leading to unauthorized access or data breaches. The vulnerability exists from the plugin's inception through version 2.3.0. The CVSS vector for this vulnerability is CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L, indicating that the attack vector is network-based, requires high complexity, low privileges, no user interaction, and can affect confidentiality, integrity, and availability.

Defensive priority

Medium priority should be given to addressing CVE-2026-39670 due to its potential impact. Although the CVSS score is medium, the nature of SSRF vulnerabilities can lead to significant risks, including unauthorized access and data leakage. Therefore, it is recommended to update the Visual Link Preview plugin to a version that mitigates this vulnerability.

Recommended defensive actions

  • Update the Visual Link Preview plugin to a version beyond 2.3.0, if available.
  • Review server configurations and network access controls to mitigate potential impacts of SSRF.
  • Monitor for suspicious activity that could indicate exploitation attempts.

Evidence notes

The CVE record for CVE-2026-39670 was published on 2026-04-08T09:16:38.423Z and last modified on 2026-07-24T20:10:00.147Z. The NVD entry for this CVE is currently Deferred. Information about the vulnerability was obtained from Patchstack, indicating a Server-Side Request Forgery (SSRF) vulnerability in the Visual Link Preview plugin.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-08T09:16:38.423Z and has not been modified since then. The NVD entry is currently Deferred.