Description
WordPress Plugin Visual Link Preview is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently get the titles of password-protected posts, or search through content of Draft posts. WordPress Plugin Visual Link Preview version 2.2.2 is vulnerable; prior versions are also affected.
Remediation
Update to plugin version 2.2.3 or latest
References
https://sploitus.com/exploit?id=WPEX-ID:854B23D9-E3F8-4835-8D29-140C580F11C9
https://plugins.svn.wordpress.org/visual-link-preview/trunk/readme.txt
Related Vulnerabilities
Joomla! Core 1.7.x Cross-Site Scripting (1.7.0 - 1.7.3)
WordPress Plugin WP-DBManager Arbitrary File Deletion (2.79.1)
WordPress Plugin RSS Includes Pages Unspecified Vulnerability (3.1)
WordPress Plugin Rezgo Online Booking Cross-Site Scripting (1.8.6)
WordPress Plugin Ads in bottom right Multiple Vulnerabilities (1.0)