NA

CVE-2022-4950

Published: 07/06/2023 Updated: 07/11/2023
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Several WordPress plugins developed by Cool Plugins are vulnerable to arbitrary plugin installation and activation that can lead to remote code execution by authenticated attackers with minimal permissions, such as a subscriber.

Vulnerable Product Search on Vulmon Subscribe to Product

coolplugins the events calendar countdown addon

coolplugins events-notification-bar-addon

coolplugins cool timeline

coolplugins events shortcodes for the events calendar

coolplugins event single page builder for the event calendar

coolplugins events search for the events calendar

coolplugins events widgets for elementor and the events calendar

coolplugins cryptocurrency widgets for elementor

coolplugins cryptocurrency widgets

cryptocurrency payment \\& donation box plugins cryptocurrency payment \\& donation box