Lucene search

K
wpexploitLana CodesWPEX-ID:5A69965D-D243-4D51-B7A4-D6F4B199ABF1
HistoryJan 17, 2023 - 12:00 a.m.

WP FullCalendar < 1.5 - Unauthenticated Arbitrary Post Access

2023-01-1700:00:00
Lana Codes
204
fullcalendar arbitrary post access unauthenticated user exploit example url admin-ajax.php wpfc_qtip_content post id 1

0.001 Low

EPSS

Percentile

32.2%

The plugin does not ensure that the post retrieved via an AJAX action is public and can be accessed by the user making the request, allowing unauthenticated attackers to get the content of arbitrary posts, including draft/private as well as password-protected ones.

Open the below URL as an unauthenticated user, and this will display the content of the post with ID 1, even if they are draft/private/password protected:

https://example.com/wp-admin/admin-ajax.php?action=wpfc_qtip_content&post_id=1

0.001 Low

EPSS

Percentile

32.2%

Related for WPEX-ID:5A69965D-D243-4D51-B7A4-D6F4B199ABF1