CVE-2022-4950
07.06.2023, 02:15
Several WordPress plugins developed by Cool Plugins are vulnerable to arbitrary plugin installation and activation that can lead to remote code execution by authenticated attackers with minimal permissions, such as a subscriber.Enginsight
Vendor | Product | Version |
---|---|---|
coolplugins | cool_timeline | 𝑥 < 2.4 |
coolplugins | cryptocurrency_widgets | 𝑥 < 2.5.1 |
coolplugins | cryptocurrency_widgets_for_elementor | 𝑥 < 1.3 |
coolplugins | event_single_page_builder_for_the_event_calendar | 𝑥 < 1.6 |
coolplugins | events-notification-bar-addon | 𝑥 < 1.6 |
coolplugins | events_search_for_the_events_calendar | 𝑥 < 1.2 |
coolplugins | events_shortcodes_for_the_events_calendar | 𝑥 < 2.0 |
coolplugins | events_widgets_for_elementor_and_the_events_calendar | 𝑥 < 1.5 |
coolplugins | the_events_calendar_countdown_addon | 𝑥 < 1.4 |
cryptocurrency_payment_\&_donation_box_plugins | cryptocurrency_payment_\&_donation_box | 𝑥 < 1.8 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References