Beveiligingsadvies

CVE-2022-3891

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2023-02-13 14:32:26
Laatst bijgewerkt 2025-03-21 14:21:49
Toegewezen door WPScan
CVSS-score 5.3
Status PUBLISHED

Beschrijving

The WP FullCalendar WordPress plugin before 1.5 does not ensure that the post retrieved via an AJAX action is public and can be accessed by the user making the request, allowing unauthenticated attackers to get the content of arbitrary posts, including draft/private as well as password-protected ones.