Description
WordPress Plugin Visual Link Preview is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently get the titles of password-protected posts, or search through content of Draft posts. WordPress Plugin Visual Link Preview version 2.2.2 is vulnerable; prior versions are also affected.
Remediation
Update to plugin version 2.2.3 or latest
References
https://sploitus.com/exploit?id=WPEX-ID:854B23D9-E3F8-4835-8D29-140C580F11C9
https://plugins.svn.wordpress.org/visual-link-preview/trunk/readme.txt
Related Vulnerabilities
Oracle JRE CVE-2014-2421 Vulnerability (CVE-2014-2421)
Internet Information Services Other Vulnerability (CVE-2002-0079)
WordPress Plugin WPMK Ajax Finder Cross-Site Request Forgery (1.0.1)
PHP Numeric Errors Vulnerability (CVE-2016-4344)
Drupal Improper Input Validation Vulnerability (CVE-2007-6299)