CVE-2022-3891

CVE-2022-3891

The WP FullCalendar WordPress plugin before 1.5 does not ensure that the post retrieved via an AJAX action is public and can be accessed by the user making the request, allowing unauthenticated attackers to get the content of arbitrary posts, including draft/private as well as password-protected ones.

Source: CVE-2022-3891

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다