Description
WordPress Plugin Visual Link Preview is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently get the titles of password-protected posts, or search through content of Draft posts. WordPress Plugin Visual Link Preview version 2.2.2 is vulnerable; prior versions are also affected.
Remediation
Update to plugin version 2.2.3 or latest
References
https://sploitus.com/exploit?id=WPEX-ID:854B23D9-E3F8-4835-8D29-140C580F11C9
https://plugins.svn.wordpress.org/visual-link-preview/trunk/readme.txt
Related Vulnerabilities
PmWiki Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2011-4453)
WordPress Plugin Shariff for WordPress Cross-Site Scripting (1.0.7)
WordPress Plugin Google +1 by BestWebSoft Cross-Site Scripting (1.1.6)
WordPress Plugin WP Cerber Security, Anti-spam & Malware Scan Cross-Site Request Forgery (2.0.1.6)