Description
WordPress Plugin WP FullCalendar is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently get the content of arbitrary posts, including draft/private as well as password-protected ones. WordPress Plugin WP FullCalendar version 1.4.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.5 or latest
References
https://sploitus.com/exploit?id=WPEX-ID:5A69965D-D243-4D51-B7A4-D6F4B199ABF1
https://plugins.svn.wordpress.org/wp-fullcalendar/trunk/readme.txt
Related Vulnerabilities
WordPress Plugin Husker Portfolio Cross-Site Request Forgery (0.3)
WordPress Plugin BigBlueButton Cross-Site Scripting (2.2.3)
WordPress Plugin bbPress Multiple Vulnerabilities (2.6.4)
SugarCRM Gain Sensitive Information Vulnerability (CVE-2004-1226)
WordPress Plugin Candidate Application Form Arbitrary File Download (1.0)