The Last Viewed Posts by WPBeginner plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.1 via the 'get_legacy_cookies' function. This makes it possible for unauthenticated attackers to extract sensitive data including titles and permalinks of private, password-protected, pending, and draft posts.
https://plugins.trac.wordpress.org/changeset/3205041/
https://plugins.trac.wordpress.org/browser/last-viewed-posts/trunk/inc/namespace.php#L131