Several WordPress plugins developed by Cool Plugins are vulnerable to arbitrary plugin installation and activation that can lead to remote code execution by authenticated attackers with minimal permissions, such as a subscriber.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Coolplugins
Subscribe
|
Cool Timeline
Subscribe
Cryptocurrency Widgets
Subscribe
Cryptocurrency Widgets For Elementor
Subscribe
Event Single Page Builder For The Event Calendar
Subscribe
Events-notification-bar-addon
Subscribe
Events Search For The Events Calendar
Subscribe
Events Shortcodes For The Events Calendar
Subscribe
Events Widgets For Elementor And The Events Calendar
Subscribe
The Events Calendar Countdown Addon
Subscribe
|
|
Cryptocurrency Payment \& Donation Box Plugins
Subscribe
|
Cryptocurrency Payment \& Donation Box
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-52203 | Several WordPress plugins developed by Cool Plugins are vulnerable to arbitrary plugin installation and activation that can lead to remote code execution by authenticated attackers with minimal permissions, such as a subscriber. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 23 Dec 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2024-12-23T16:20:36.227Z
Reserved: 2023-06-06T13:39:44.796Z
Link: CVE-2022-4950
Updated: 2024-08-03T01:55:46.079Z
Status : Modified
Published: 2023-06-07T02:15:15.813
Modified: 2024-11-21T07:36:18.810
Link: CVE-2022-4950
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD