Understanding the Link Whisper Free Plugin Vulnerability
A notable security flaw has been discovered in the Link Whisper Free WordPress plugin, identified as CVE-2026-1900. This vulnerability allows unauthorized individuals to make changes to your plugin settings without needing to log in. This issue stems from a part of the plugin that is meant to connect with other services (known as a REST endpoint) being openly accessible, which it shouldn’t be.
CVE Details
This vulnerability affects the Link Whisper Free WordPress plugin. It was publicly disclosed on April 7, 2026, and is currently rated with a Medium severity. The status of this vulnerability is Analyzed, meaning it has been thoroughly investigated and confirmed.
Affected Products
Users of the Link Whisper Free WordPress plugin running any version older than 0.9.1 are at risk. It is crucial for anyone using this plugin to verify their current version to determine if they are impacted.
Current Status
As of its last modification date on April 13, 2026, this vulnerability is in an “Analyzed” status. This indicates that the details of the flaw are well-understood and documented.
Severity Level
With a CVSS score of 6.5, this vulnerability is classified as Medium severity. While not the highest level of risk, it still poses a significant concern. An attacker exploiting this could potentially alter important settings within your WordPress site through the Link Whisper plugin, which could disrupt its functionality or lead to further compromises. The ability to make unauthenticated changes highlights the danger.
Possible Solutions
The most important step to protect your WordPress site is to update the Link Whisper Free plugin immediately. The vulnerability has been addressed in version 0.9.1 and all subsequent versions. Ensure your plugin is updated to 0.9.1 or later to apply the necessary security patches and close this unauthorized access point.
References
https://wpscan.com/vulnerability/dc10b627-7981-4c53-bc9d-e87418f3fcfc/
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1900

