Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-1900

23
FAUCET Score

CVE-2026-1900 is an authentication bypass vulnerability affecting the Link Whisper Free WordPress plugin versions prior to 0.9.1. The vulnerability stems from an improperly secured REST API endpoint that permits unauthenticated users to modify plugin settings without authorization. This flaw exposes WordPress installations using the affected plugin to potential configuration tampering and data integrity issues. The vulnerability presents a medium severity risk with a CVSS score of 6.5, characterized by network-based exploitation requiring no authentication or user interaction. While the attack has low complexity and can impact both confidentiality and integrity of plugin settings, the availability of systems remains unaffected. Organizations using this plugin should prioritize patching to version 0.9.1 or later to remediate the exposure. The vulnerability is not currently listed on the CISA Known Exploited Vulnerabilities catalog and shows minimal community attention with an exceptionally low EPSS score of 0.00033. There is no evidence of active exploitation in the wild at this time. However, given the straightforward nature of the vulnerability and the public disclosure of the REST endpoint flaw, security teams should monitor for proof-of-concept exploit development and apply patches proactively.

Impacted Technologies

VendorProductVersion(s)CPE
< 0.9.1CPE matchmatch criteria
cpe:2.3:a:linkwhisper:link_whisper:*:*:*:*:free:wordpress:*:*

CVSS Data

CVSS version used by this source: 3.1

6.5MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
2.5
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.19%
Probability of exploitation in next 30 days
EPSS Percentile
8.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0019 is in the 1st percentile among its peer group of 23,690 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

wpscan.com / vulnerability/dc10b627-7981-4c53-bc9d-e87418f3fcfc
ExploitThird Party Advisory