The WP FullCalendar WordPress plugin before 1.5 does not ensure that the post retrieved via an AJAX action is public and can be accessed by the user making the request, allowing unauthenticated attackers to get the content of arbitrary posts, including draft/private as well as password-protected ones.
History

Fri, 21 Mar 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2023-02-13T14:32:26.964Z

Updated: 2025-03-21T14:21:49.317Z

Reserved: 2022-11-08T11:45:27.277Z

Link: CVE-2022-3891

cve-icon Vulnrichment

Updated: 2024-08-03T01:20:58.483Z

cve-icon NVD

Status : Modified

Published: 2023-02-13T15:15:14.860

Modified: 2025-03-21T15:15:37.947

Link: CVE-2022-3891

cve-icon Redhat

No data.