CVE-2022-3891
Last modified
CVE-2022-3891 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. The WP FullCalendar WordPress plugin before 1.5 does not ensure that the post retrieved via an AJAX action is public and can be accessed by the user making the request, allowing unauthenticated attackers to get the content of arbitrary posts, including draft/private as well as password-protected ones.. EPSS estimates a 0.69% chance of exploitation in the next 30 days.
Description
The WP FullCalendar WordPress plugin before 1.5 does not ensure that the post retrieved via an AJAX action is public and can be accessed by the user making the request, allowing unauthenticated attackers to get the content of arbitrary posts, including draft/private as well as password-protected ones.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Pixelite | Wp Fullcalendar | < 1.5 |
References
- https://wpscan.com/vulnerability/5a69965d-d243-4d51-b7a4-d6f4b199abf1Exploit, Third Party Advisory
- https://wpscan.com/vulnerability/5a69965d-d243-4d51-b7a4-d6f4b199abf1Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-3891?
How severe is CVE-2022-3891?
How do I fix CVE-2022-3891?
Are you affected by CVE-2022-3891?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
