Extension WordPress
Vulnérabilités Visual Link Preview
Cette page rassemble les failles publiées pour Visual Link Preview, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Visual Link Preview
6 fiches
Visual Link Preview <= 2.3.1 – Authenticated (Subscriber+) Sensitive Information Exposure
The Visual Link Preview plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.3.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive user or…
*-2.3.1
2.4.0
17/06/2026
Visual Link Preview <= 2.4.1 – Authenticated (Subscriber+) Information Exposure
The Visual Link Preview plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive user or…
*-2.4.1
2.4.2
02/06/2026
Visual Link Preview <= 2.3.0 – Authenticated (Contributor+) Server-Side Request Forgery
The Visual Link Preview plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.3.0. This makes it possible for authenticated attackers, with Contributor-level access and above, to make web requests to…
*-2.3.0
2.3.1
19/02/2026
Visual Link Preview <= 2.2.9 – Missing Authorization
The Visual Link Preview plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.2.9. This makes it possible for authenticated attackers, with Contributor-level…
*-2.2.9
2.3.0
18/01/2026
Visual Link Preview <= 2.2.7 – Authenticated (Contributor+) Stored Cross-Site Scripting via visual-link-preview Shortcode
The Visual Link Preview plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's visual-link-preview shortcode in versions up to, and including, 2.2.7 due to insufficient input sanitization and output escaping on user supplied attributes. This…
*-2.2.7
2.2.8
04/11/2025
Visual Link Preview <= 2.2.2 – Unauthorised AJAX Calls
The Visual Link Preview WordPress plugin before 2.2.3 does not enforce authorisation on several AJAX actions and has the CSRF nonce displayed for all authenticated users, allowing any authenticated user (such as subscriber) to call them and 1)…
[*, 2.2.3)
2.2.3
18/08/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.