The WP FullCalendar WordPress plugin before 1.5 does not ensure that the post retrieved via an AJAX action is public and can be accessed by the user making the request, allowing unauthenticated attackers to get the content of arbitrary posts, including draft/private as well as password-protected ones.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2023-02-13T14:32:26.964Z

Updated: 2024-08-03T01:20:58.483Z

Reserved: 2022-11-08T11:45:27.277Z

Link: CVE-2022-3891

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-02-13T15:15:14.860

Modified: 2023-11-07T03:51:55.653

Link: CVE-2022-3891

cve-icon Redhat

No data.