The WP FullCalendar WordPress plugin before 1.5 does not ensure that the post retrieved via an AJAX action is public and can be accessed by the user making the request, allowing unauthenticated attackers to get the content of arbitrary posts, including draft/private as well as password-protected ones.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: WPScan
Published: 2023-02-13T14:32:26.964Z
Updated: 2024-08-03T01:20:58.483Z
Reserved: 2022-11-08T11:45:27.277Z
Link: CVE-2022-3891
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-02-13T15:15:14.860
Modified: 2023-11-07T03:51:55.653
Link: CVE-2022-3891
Redhat
No data.