CVE-2026-1900Disclosure(linkwhisper / link_whisper)

LOWCVSS 6.5 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Link Whisper Free WordPress plugin before 0.9.1 has a publicly accessible REST endpoint that allows unauthenticated settings updates.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • link_whisper

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 2 mentions (2026-04-07); latest day: 2
  • 4 total mentions across 2 days

Affected systems

Products
link_whisper

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-04-07: 2Mentions · 2026-04-19: 2Technical Details · 2026-04-07: 2Technical Details · 2026-04-19: 204-0704-19
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Full discourse4 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-1900 The Link Whisper Free WordPress plugin before 0.9.1 has a publicly accessible REST endpoint that allows unauthenticated settings updates. https://www.cve.org/CVERecord?id=CVE-2026-1900 ----- Traducción: CVE-2026-1900 El plugin gratuito de WordPress Link… http://infoflow.cloud`

    Post summary

    Initial disclosure of CVE‑2026‑1900 detailing an unauthenticated REST endpoint in the Link Whisper WordPress plugin, enabling unauthorized settings changes.

    0000044
    72 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1900 The Link Whisper Free WordPress plugin before 0.9.1 has a publicly accessible REST endpoint that allows unauthenticated settings updates. https://www.cve.org/CVERecord?id=CVE-2026-1900

    Post summary

    The Link Whisper Free WordPress plugin (v<0.9.1) exposes a REST endpoint enabling unauthenticated settings updates, revealing a significant security flaw.

    00000267
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-1900 Unauthenticated Settings Update via Public REST Endpoint in Link Whisper Free WordPress Plugin https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-1900

    Post summary

    The post announces CVE-2026-1900, revealing that unauthenticated users can update settings via a public REST endpoint in the Link Whisper Free WordPress plugin; it offers no PoC, exploit, active exploitation evidence, or patch information.

    0000049
    4.0K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-1900 - Link Whisper Free &amp;lt; 0.9.1 - Unauthenticated Settings and User Meta Update Intel Report: https://ift.tt/76WrMTq

    Post summary

    A new vulnerability (CVE-2026-1900) affecting Link Whisper Free versions under 0.9.1, allowing unauthenticated updates to settings and user metadata, has been disclosed with an intel report link.

    0000034
    281 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applinkwhisperlink_whisper-wordpress-

Explore more