Visual Link Preview
Visual Link Preview has 6 disclosed vulnerabilities in the WordSec catalog, reported between 2021 and 2026; all 6 are fixed as of September 2026. Their average CVSS score is 5.2, and the most serious one scores 6.4 out of 10. 2026 was the busiest year with 4 disclosures.
The most common weakness is Exposure Of Sensitive Information To An Unauthorized Actor, behind 2 of the records (33%). Other recurring categories include Improper Access Control, Improper Neutralization Of Script-Related HTML Tags In A Web Page (Basic XSS).
Every one of the 6 issues recorded for Visual Link Preview has a vendor fix available, so running the current release closes all known holes.
6 independent researchers contributed these findings, one record each. Visual Link Preview is installed on roughly 10,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2026-39670Visual Link Preview <= 2.3.0 - Authenticated (Contributor+) Server-Side Request Forgery
Read the full analysisVulnerability Records

Visual Link Preview
Author
Brecht
Easily create a Facebook-like link preview for any link on your website. You can choose the image and text to display and create your very own custom template. The default template can be styled from the settings to match your website. Some examples of what you could use this for: A call to action for your affiliate links Promote WooCommerce products on your website List sources for your article A weekly posty of interesting websites you’ve found Link to related posts on your own website … It does not require any database lookups, which means even having many of these blocks on a page should not affect performance. Compatible with both the Classic and Gutenberg Block Editor using shortcodes and blocks. Also includes full Elementor support with a dedicated widget for easy integration into your Elementor pages. The plugin includes multiple URL metadata providers (PHP, Microlink API, and LinkPreview API) with automatic fallback switching. If one provider fails to fetch link information, the plugin automatically tries the next available provider. You can also manually retry with a different provider if needed. Need help? Check out our documentation! This plugin is in active development. Feel free to contact us with any feature requests or ideas.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C