cleantalk
Vulnerabilities and Security Researches

WP FullCalendar, CVE-2022-3891

CVE, Research URL

CVE-2022-3891

Application

WP FullCalendar

Published on
Feb 13, 2023
Research Description
The WP FullCalendar WordPress plugin before 1.5 does not ensure that the post retrieved via an AJAX action is public and can be accessed by the user making the request, allowing unauthenticated attackers to get the content of arbitrary posts, including draft/private as well as password-protected ones.
Affected versions
max 1.5.
Status
vulnerable