{"id":3538,"date":"2026-04-13T20:31:38","date_gmt":"2026-04-13T20:31:38","guid":{"rendered":"https:\/\/www.ucartz.com\/updates\/link-whisper-free-wordpress-plugin-unauthenticated-settings-update-vulnerability-cve-2026-1900-medium-severity\/"},"modified":"2026-04-13T20:31:38","modified_gmt":"2026-04-13T20:31:38","slug":"link-whisper-free-wordpress-plugin-unauthenticated-settings-update-vulnerability-cve-2026-1900-medium-severity","status":"publish","type":"post","link":"https:\/\/www.ucartz.com\/updates\/link-whisper-free-wordpress-plugin-unauthenticated-settings-update-vulnerability-cve-2026-1900-medium-severity\/","title":{"rendered":"Link Whisper Free WordPress Plugin Unauthenticated Settings Update Vulnerability (CVE-2026-1900) \u2014 Medium Severity"},"content":{"rendered":"<h2>Understanding the Link Whisper Free Plugin Vulnerability<\/h2>\n<p>A notable security flaw has been discovered in the Link Whisper Free WordPress plugin, identified as CVE-2026-1900. This vulnerability allows unauthorized individuals to make changes to your plugin settings without needing to log in. This issue stems from a part of the plugin that is meant to connect with other services (known as a REST endpoint) being openly accessible, which it shouldn&#8217;t be.<\/p>\n<h2>CVE Details<\/h2>\n<p>This vulnerability affects the <strong>Link Whisper Free WordPress plugin<\/strong>. It was publicly disclosed on <strong>April 7, 2026<\/strong>, and is currently rated with a <strong>Medium<\/strong> severity. The status of this vulnerability is <strong>Analyzed<\/strong>, meaning it has been thoroughly investigated and confirmed.<\/p>\n<h2>Affected Products<\/h2>\n<p>Users of the Link Whisper Free WordPress plugin running any version older than <strong>0.9.1<\/strong> are at risk. It is crucial for anyone using this plugin to verify their current version to determine if they are impacted.<\/p>\n<h2>Current Status<\/h2>\n<p>As of its last modification date on April 13, 2026, this vulnerability is in an &#8220;Analyzed&#8221; status. This indicates that the details of the flaw are well-understood and documented.<\/p>\n<h2>Severity Level<\/h2>\n<p>With a CVSS score of 6.5, this vulnerability is classified as Medium severity. While not the highest level of risk, it still poses a significant concern. An attacker exploiting this could potentially alter important settings within your WordPress site through the Link Whisper plugin, which could disrupt its functionality or lead to further compromises. The ability to make unauthenticated changes highlights the danger.<\/p>\n<h2>Possible Solutions<\/h2>\n<p>The most important step to protect your WordPress site is to update the Link Whisper Free plugin immediately. The vulnerability has been addressed in version <strong>0.9.1<\/strong> and all subsequent versions. Ensure your plugin is updated to 0.9.1 or later to apply the necessary security patches and close this unauthorized access point.<\/p>\n<h2>References<\/h2>\n<p>https:\/\/wpscan.com\/vulnerability\/dc10b627-7981-4c53-bc9d-e87418f3fcfc\/<\/p>\n<p>https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2026-1900<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Understanding the Link Whisper Free Plugin Vulnerability A notable security flaw has been discovered in the Link Whisper Free WordPress plugin, identified as CVE-2026-1900. This vulnerability allows unauthorized individuals to make changes to your plugin settings without needing to log in. This issue stems from a part of the plugin that is meant to connect [&hellip;]<\/p>\n","protected":false},"author":17,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[1078,715,1079,727,719],"class_list":["post-3538","post","type-post","status-publish","format-standard","hentry","category-security","tag-link-whisper","tag-plugin-vulnerability","tag-rest-api-security","tag-unauthenticated-access","tag-wordpress-security"],"blocksy_meta":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Link Whisper Free WordPress Plugin Unauthenticated Settings Update Vulnerability (CVE-2026-1900) \u2014 Medium Severity - Web Hosting and IT Consultancy Services<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.ucartz.com\/updates\/link-whisper-free-wordpress-plugin-unauthenticated-settings-update-vulnerability-cve-2026-1900-medium-severity\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Link Whisper Free WordPress Plugin Unauthenticated Settings Update Vulnerability (CVE-2026-1900) \u2014 Medium Severity - Web Hosting and IT Consultancy Services\" \/>\n<meta property=\"og:description\" content=\"Understanding the Link Whisper Free Plugin Vulnerability A notable security flaw has been discovered in the Link Whisper Free WordPress plugin, identified as CVE-2026-1900. This vulnerability allows unauthorized individuals to make changes to your plugin settings without needing to log in. This issue stems from a part of the plugin that is meant to connect [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.ucartz.com\/updates\/link-whisper-free-wordpress-plugin-unauthenticated-settings-update-vulnerability-cve-2026-1900-medium-severity\/\" \/>\n<meta property=\"og:site_name\" content=\"Web Hosting and IT Consultancy Services\" \/>\n<meta property=\"article:published_time\" content=\"2026-04-13T20:31:38+00:00\" \/>\n<meta name=\"author\" content=\"Alex Joseph\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Alex Joseph\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/link-whisper-free-wordpress-plugin-unauthenticated-settings-update-vulnerability-cve-2026-1900-medium-severity\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/link-whisper-free-wordpress-plugin-unauthenticated-settings-update-vulnerability-cve-2026-1900-medium-severity\\\/\"},\"author\":{\"name\":\"Alex Joseph\",\"@id\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/#\\\/schema\\\/person\\\/1ba9bfab02a76dee216c9f55bb634e56\"},\"headline\":\"Link Whisper Free WordPress Plugin Unauthenticated Settings Update Vulnerability (CVE-2026-1900) \u2014 Medium Severity\",\"datePublished\":\"2026-04-13T20:31:38+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/link-whisper-free-wordpress-plugin-unauthenticated-settings-update-vulnerability-cve-2026-1900-medium-severity\\\/\"},\"wordCount\":330,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/#organization\"},\"keywords\":[\"Link Whisper\",\"Plugin Vulnerability\",\"REST API Security\",\"Unauthenticated Access\",\"WordPress Security\"],\"articleSection\":[\"Security\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/link-whisper-free-wordpress-plugin-unauthenticated-settings-update-vulnerability-cve-2026-1900-medium-severity\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/link-whisper-free-wordpress-plugin-unauthenticated-settings-update-vulnerability-cve-2026-1900-medium-severity\\\/\",\"url\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/link-whisper-free-wordpress-plugin-unauthenticated-settings-update-vulnerability-cve-2026-1900-medium-severity\\\/\",\"name\":\"Link Whisper Free WordPress Plugin Unauthenticated Settings Update Vulnerability (CVE-2026-1900) \u2014 Medium Severity - Web Hosting and IT Consultancy Services\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/#website\"},\"datePublished\":\"2026-04-13T20:31:38+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/link-whisper-free-wordpress-plugin-unauthenticated-settings-update-vulnerability-cve-2026-1900-medium-severity\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/link-whisper-free-wordpress-plugin-unauthenticated-settings-update-vulnerability-cve-2026-1900-medium-severity\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/link-whisper-free-wordpress-plugin-unauthenticated-settings-update-vulnerability-cve-2026-1900-medium-severity\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Link Whisper Free WordPress Plugin Unauthenticated Settings Update Vulnerability (CVE-2026-1900) \u2014 Medium Severity\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/#website\",\"url\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/\",\"name\":\"Web Hosting and IT Consultancy Services\",\"description\":\"Discover the Potential of Digital Transformation through Effortless Hosting and Professional IT Consulting!\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/#organization\",\"name\":\"Web Hosting and IT Consultancy Services\",\"url\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/wp-content\\\/uploads\\\/2025\\\/12\\\/ucartzLogo-1.png\",\"contentUrl\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/wp-content\\\/uploads\\\/2025\\\/12\\\/ucartzLogo-1.png\",\"width\":165,\"height\":50,\"caption\":\"Web Hosting and IT Consultancy Services\"},\"image\":{\"@id\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/#\\\/schema\\\/person\\\/1ba9bfab02a76dee216c9f55bb634e56\",\"name\":\"Alex Joseph\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/0969fa5fefa2739cbd6fd5eaf04fed619e19f40d42e4a42650090606944ff747?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/0969fa5fefa2739cbd6fd5eaf04fed619e19f40d42e4a42650090606944ff747?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/0969fa5fefa2739cbd6fd5eaf04fed619e19f40d42e4a42650090606944ff747?s=96&d=mm&r=g\",\"caption\":\"Alex Joseph\"},\"description\":\"Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.\",\"url\":\"https:\\\/\\\/www.ucartz.com\\\/updates\\\/author\\\/alexjoseph\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Link Whisper Free WordPress Plugin Unauthenticated Settings Update Vulnerability (CVE-2026-1900) \u2014 Medium Severity - Web Hosting and IT Consultancy Services","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.ucartz.com\/updates\/link-whisper-free-wordpress-plugin-unauthenticated-settings-update-vulnerability-cve-2026-1900-medium-severity\/","og_locale":"en_US","og_type":"article","og_title":"Link Whisper Free WordPress Plugin Unauthenticated Settings Update Vulnerability (CVE-2026-1900) \u2014 Medium Severity - Web Hosting and IT Consultancy Services","og_description":"Understanding the Link Whisper Free Plugin Vulnerability A notable security flaw has been discovered in the Link Whisper Free WordPress plugin, identified as CVE-2026-1900. This vulnerability allows unauthorized individuals to make changes to your plugin settings without needing to log in. This issue stems from a part of the plugin that is meant to connect [&hellip;]","og_url":"https:\/\/www.ucartz.com\/updates\/link-whisper-free-wordpress-plugin-unauthenticated-settings-update-vulnerability-cve-2026-1900-medium-severity\/","og_site_name":"Web Hosting and IT Consultancy Services","article_published_time":"2026-04-13T20:31:38+00:00","author":"Alex Joseph","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Alex Joseph","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.ucartz.com\/updates\/link-whisper-free-wordpress-plugin-unauthenticated-settings-update-vulnerability-cve-2026-1900-medium-severity\/#article","isPartOf":{"@id":"https:\/\/www.ucartz.com\/updates\/link-whisper-free-wordpress-plugin-unauthenticated-settings-update-vulnerability-cve-2026-1900-medium-severity\/"},"author":{"name":"Alex Joseph","@id":"https:\/\/www.ucartz.com\/updates\/#\/schema\/person\/1ba9bfab02a76dee216c9f55bb634e56"},"headline":"Link Whisper Free WordPress Plugin Unauthenticated Settings Update Vulnerability (CVE-2026-1900) \u2014 Medium Severity","datePublished":"2026-04-13T20:31:38+00:00","mainEntityOfPage":{"@id":"https:\/\/www.ucartz.com\/updates\/link-whisper-free-wordpress-plugin-unauthenticated-settings-update-vulnerability-cve-2026-1900-medium-severity\/"},"wordCount":330,"commentCount":0,"publisher":{"@id":"https:\/\/www.ucartz.com\/updates\/#organization"},"keywords":["Link Whisper","Plugin Vulnerability","REST API Security","Unauthenticated Access","WordPress Security"],"articleSection":["Security"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.ucartz.com\/updates\/link-whisper-free-wordpress-plugin-unauthenticated-settings-update-vulnerability-cve-2026-1900-medium-severity\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.ucartz.com\/updates\/link-whisper-free-wordpress-plugin-unauthenticated-settings-update-vulnerability-cve-2026-1900-medium-severity\/","url":"https:\/\/www.ucartz.com\/updates\/link-whisper-free-wordpress-plugin-unauthenticated-settings-update-vulnerability-cve-2026-1900-medium-severity\/","name":"Link Whisper Free WordPress Plugin Unauthenticated Settings Update Vulnerability (CVE-2026-1900) \u2014 Medium Severity - Web Hosting and IT Consultancy Services","isPartOf":{"@id":"https:\/\/www.ucartz.com\/updates\/#website"},"datePublished":"2026-04-13T20:31:38+00:00","breadcrumb":{"@id":"https:\/\/www.ucartz.com\/updates\/link-whisper-free-wordpress-plugin-unauthenticated-settings-update-vulnerability-cve-2026-1900-medium-severity\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.ucartz.com\/updates\/link-whisper-free-wordpress-plugin-unauthenticated-settings-update-vulnerability-cve-2026-1900-medium-severity\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.ucartz.com\/updates\/link-whisper-free-wordpress-plugin-unauthenticated-settings-update-vulnerability-cve-2026-1900-medium-severity\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.ucartz.com\/updates\/"},{"@type":"ListItem","position":2,"name":"Link Whisper Free WordPress Plugin Unauthenticated Settings Update Vulnerability (CVE-2026-1900) \u2014 Medium Severity"}]},{"@type":"WebSite","@id":"https:\/\/www.ucartz.com\/updates\/#website","url":"https:\/\/www.ucartz.com\/updates\/","name":"Web Hosting and IT Consultancy Services","description":"Discover the Potential of Digital Transformation through Effortless Hosting and Professional IT Consulting!","publisher":{"@id":"https:\/\/www.ucartz.com\/updates\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.ucartz.com\/updates\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.ucartz.com\/updates\/#organization","name":"Web Hosting and IT Consultancy Services","url":"https:\/\/www.ucartz.com\/updates\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.ucartz.com\/updates\/#\/schema\/logo\/image\/","url":"https:\/\/www.ucartz.com\/updates\/wp-content\/uploads\/2025\/12\/ucartzLogo-1.png","contentUrl":"https:\/\/www.ucartz.com\/updates\/wp-content\/uploads\/2025\/12\/ucartzLogo-1.png","width":165,"height":50,"caption":"Web Hosting and IT Consultancy Services"},"image":{"@id":"https:\/\/www.ucartz.com\/updates\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.ucartz.com\/updates\/#\/schema\/person\/1ba9bfab02a76dee216c9f55bb634e56","name":"Alex Joseph","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/0969fa5fefa2739cbd6fd5eaf04fed619e19f40d42e4a42650090606944ff747?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/0969fa5fefa2739cbd6fd5eaf04fed619e19f40d42e4a42650090606944ff747?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/0969fa5fefa2739cbd6fd5eaf04fed619e19f40d42e4a42650090606944ff747?s=96&d=mm&r=g","caption":"Alex Joseph"},"description":"Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.","url":"https:\/\/www.ucartz.com\/updates\/author\/alexjoseph\/"}]}},"_links":{"self":[{"href":"https:\/\/www.ucartz.com\/updates\/wp-json\/wp\/v2\/posts\/3538","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.ucartz.com\/updates\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.ucartz.com\/updates\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.ucartz.com\/updates\/wp-json\/wp\/v2\/users\/17"}],"replies":[{"embeddable":true,"href":"https:\/\/www.ucartz.com\/updates\/wp-json\/wp\/v2\/comments?post=3538"}],"version-history":[{"count":0,"href":"https:\/\/www.ucartz.com\/updates\/wp-json\/wp\/v2\/posts\/3538\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.ucartz.com\/updates\/wp-json\/wp\/v2\/media?parent=3538"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.ucartz.com\/updates\/wp-json\/wp\/v2\/categories?post=3538"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.ucartz.com\/updates\/wp-json\/wp\/v2\/tags?post=3538"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}