The WP FullCalendar WordPress plugin before 1.5 does not ensure that the post retrieved via an AJAX action is public and can be accessed by the user making the request, allowing unauthenticated attackers to get the content of arbitrary posts, including draft/private as well as password-protected ones.
Metrics
Affected Vendors & Products
References
History
Fri, 21 Mar 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: WPScan
Published: 2023-02-13T14:32:26.964Z
Updated: 2025-03-21T14:21:49.317Z
Reserved: 2022-11-08T11:45:27.277Z
Link: CVE-2022-3891

Updated: 2024-08-03T01:20:58.483Z

Status : Modified
Published: 2023-02-13T15:15:14.860
Modified: 2025-03-21T15:15:37.947
Link: CVE-2022-3891

No data.