VYPR
Medium severity6.5NVD Advisory· Published Jun 15, 2026· Updated Jun 15, 2026

CVE-2026-48878

CVE-2026-48878

Description

The Visual Link Preview plugin for WordPress <= 2.4.1 exposes subscriber sensitive data via an unauthenticated vulnerability, risking information disclosure.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

The Visual Link Preview plugin for WordPress <= 2.4.1 exposes subscriber sensitive data via an unauthenticated vulnerability, risking information disclosure.

Vulnerability

The Visual Link Preview plugin for WordPress versions 2.4.1 and earlier fails to properly restrict access to subscriber-sensitive data [1]. This allows any unauthenticated user to retrieve information that should only be available to authorized roles. The vulnerability resides in the plugin's data handling routines, and no special configuration is required to exploit it; the default installation is affected.

Exploitation

An attacker with network access to the WordPress site can exploit this vulnerability by sending crafted HTTP requests to the plugin's exposed endpoints. No authentication or user interaction is required. The exact request parameters are documented in the Patchstack advisory [1]. The attack is straightforward and does not require a race condition or elevated privileges.

Impact

Successful exploitation enables the attacker to view subscriber-sensitive data, which may include personally identifiable information such as email addresses, usernames, and other account metadata. This is a confidentiality breach that can lead to further attacks, such as phishing or account takeover, depending on the exposed fields [1].

Mitigation

The vulnerability is fully patched in version 2.4.2 of the plugin. Users are strongly advised to update immediately [1]. For those who cannot update, Patchstack provides a virtual mitigation rule that blocks exploitation attempts until the update is applied. No other workarounds have been disclosed.

AI Insight generated on Jun 15, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

1