Description
WordPress Plugin Visual Link Preview is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently get the titles of password-protected posts, or search through content of Draft posts. WordPress Plugin Visual Link Preview version 2.2.2 is vulnerable; prior versions are also affected.
Remediation
Update to plugin version 2.2.3 or latest
References
https://sploitus.com/exploit?id=WPEX-ID:854B23D9-E3F8-4835-8D29-140C580F11C9
https://plugins.svn.wordpress.org/visual-link-preview/trunk/readme.txt
Related Vulnerabilities
WordPress Plugin Recipes Writer Cross-Site Scripting (1.0.4)
WordPress Plugin Clockwork SMS Notfications Cross-Site Scripting (2.0.3)
WordPress Plugin Slider Hero with Animation, Video Background Unspecified Vulnerability (5.5.0)
WordPress Plugin 404 to 301-Redirect, Log and Notify 404 Errors Security Bypass (3.0.1)