Description
In Moodle 2.x and 3.x, searching of arbitrary blogs is possible because a capability check is missing.
Remediation
References
Related Vulnerabilities
WordPress Plugin The Events Calendar Cross-Site Scripting (4.8.1)
WordPress Plugin Anti Spam Protection without CAPTCHA powered by Keypic Security Bypass (2.1.2)
MySQL CVE-2017-3651 Vulnerability (CVE-2017-3651)
WordPress Plugin A Page Flip Book 'pageflipbook_language' Parameter Local File Include (2.3)