Record summary

CVE-2022-2314 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

The VR Calendar WordPress plugin through 2.3.2 lets any user execute arbitrary PHP functions on the site.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jan 1, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus

VR Calendar

CVE List2.3.2 to < 2.3.2affected
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryCRITICALWordPress VR Calendar <=2.3.2 - Remote Code ExecutionCVSS 9.8

WordPress VR Calendar plugin through 2.3.2 is susceptible to remote code execution. The plugin allows any user to execute arbitrary PHP functions on the site. An attacker can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected WordPress site.

Remediation

Update the WordPress VR Calendar plugin to version 2.3.3 or later to mitigate this vulnerability.

WeaknessesCWE-78
Authorstheamanrawat
Template tagscvecve2022wordpresswpwp-pluginrcevr-calendar-syncunauthwpscanvr_calendar_projectvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:vr_calendar_project:vr_calendar:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

2