MEDIUM
Brecht
CVE published 2026-04-08
CVE-2026-39670
A Server-Side Request Forgery (SSRF) vulnerability was discovered in the Visual Link Preview plugin for WordPress. The issue, tracked as CVE-2026-39670, allows attackers to make unauthorized requests on behalf of the server. The vulnerability affects the plugin from its inception up to and including version 2.3.0. Users of the affected versions should consider updating to a patched version, if available, [truncated]