ZeroHour

CVE-2022-3891

PoC
CVSS 3.1
5.3 medium
EPSS
<1%p51
Published
()
Modified
Description

The WP FullCalendar WordPress plugin before 1.5 does not ensure that the post retrieved via an AJAX action is public and can be accessed by the user making the request, allowing unauthenticated attackers to get the content of arbitrary posts, including draft/private as well as password-protected ones.

Vendors
pixelite
Products
wp fullcalendar
Ecosystems
WordPress
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.