We found results for “”
CVE-2022-4950
Good to know:
Date: June 6, 2023
Several WordPress plugins developed by Cool Plugins are vulnerable to arbitrary plugin installation and activation that can lead to remote code execution by authenticated attackers with minimal permissions, such as a subscriber.
Language: PHP
Severity Score
Related Resources (5)
Severity Score
Weakness Type (CWE)
Missing Authorization
CWE-862Top Fix
Upgrade Version
Upgrade to version cool-timeline - 2.4, cryptocurrency-donation-box - 1.8, cryptocurrency-price-ticker-widget - 2.5.1, cryptocurrency-widgets-for-elementor - 1.3, event-page-templates-addon-for-the-events-calendar - 1.6, events-search-addon-for-the-events-calendar - 1.2, template-events-calendar - 2.0, events-widgets-for-elementor-and-the-events-calendar - 1.5, countdown-for-the-events-calendar - 1.4, events-notification-bar-addon - 1.6
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | LOW |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | HIGH |
Integrity (I): | HIGH |
Availability (A): | HIGH |