5.3
CVSSv3

CVE-2022-3891

Published: 13/02/2023 Updated: 07/11/2023
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

The WP FullCalendar WordPress plugin prior to 1.5 does not ensure that the post retrieved via an AJAX action is public and can be accessed by the user making the request, allowing unauthenticated malicious users to get the content of arbitrary posts, including draft/private as well as password-protected ones.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

pixelite wp fullcalendar