Lucene search

K
wpvulndbLana CodesWPVDB-ID:5A69965D-D243-4D51-B7A4-D6F4B199ABF1
HistoryJan 17, 2023 - 12:00 a.m.

WP FullCalendar < 1.5 - Unauthenticated Arbitrary Post Access

2023-01-1700:00:00
Lana Codes
wpscan.com
8
wp fullcalendar plugin
unauthenticated access
arbitrary post
ajax action
draft posts
private posts
password-protected posts

EPSS

0.001

Percentile

35.5%

The plugin does not ensure that the post retrieved via an AJAX action is public and can be accessed by the user making the request, allowing unauthenticated attackers to get the content of arbitrary posts, including draft/private as well as password-protected ones.

PoC

Open the below URL as an unauthenticated user, and this will display the content of the post with ID 1, even if they are draft/private/password protected: https://example.com/wp-admin/admin-ajax.php?action=wpfc_qtip_content&amp;post;_id=1

EPSS

0.001

Percentile

35.5%

Related for WPVDB-ID:5A69965D-D243-4D51-B7A4-D6F4B199ABF1