CVE-2022-4950

Several WordPress plugins developed by Cool Plugins are vulnerable to arbitrary plugin installation and activation that can lead to remote code execution by authenticated attackers with minimal permissions, such as a subscriber.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:coolplugins:cool_timeline:*:*:*:*:*:wordpress:*:*
cpe:2.3:a:coolplugins:cryptocurrency_widgets:*:*:*:*:*:wordpress:*:*
cpe:2.3:a:coolplugins:cryptocurrency_widgets_for_elementor:*:*:*:*:*:wordpress:*:*
cpe:2.3:a:coolplugins:event_single_page_builder_for_the_event_calendar:*:*:*:*:*:wordpress:*:*
cpe:2.3:a:coolplugins:events-notification-bar-addon:*:*:*:*:*:wordpress:*:*
cpe:2.3:a:coolplugins:events_search_for_the_events_calendar:*:*:*:*:*:wordpress:*:*
cpe:2.3:a:coolplugins:events_shortcodes_for_the_events_calendar:*:*:*:*:*:wordpress:*:*
cpe:2.3:a:coolplugins:events_widgets_for_elementor_and_the_events_calendar:*:*:*:*:*:wordpress:*:*
cpe:2.3:a:coolplugins:the_events_calendar_countdown_addon:*:*:*:*:*:wordpress:*:*
cpe:2.3:a:cryptocurrency_payment_\&_donation_box_plugins:cryptocurrency_payment_\&_donation_box:*:*:*:*:*:wordpress:*:*

History

No history.

Information

Published : 2023-06-07 02:15

Updated : 2024-11-21 07:36


NVD link : CVE-2022-4950

Mitre link : CVE-2022-4950

CVE.ORG link : CVE-2022-4950


JSON object : View

Products Affected

coolplugins

  • the_events_calendar_countdown_addon
  • cryptocurrency_widgets_for_elementor
  • events_widgets_for_elementor_and_the_events_calendar
  • events-notification-bar-addon
  • events_search_for_the_events_calendar
  • events_shortcodes_for_the_events_calendar
  • cool_timeline
  • event_single_page_builder_for_the_event_calendar
  • cryptocurrency_widgets

cryptocurrency_payment_\&_donation_box_plugins

  • cryptocurrency_payment_\&_donation_box
CWE
CWE-862

Missing Authorization