CVE-2022-2314
VR Calendar < 2.3.2 - Unauthenticated Arbitrary Function Call
Record summary
CVE-2022-2314 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
The VR Calendar WordPress plugin through 2.3.2 lets any user execute arbitrary PHP functions on the site.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jan 1, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
VR Calendar | CVE List | 2.3.2 to < 2.3.2 | affected |
vr_calendarBrowse vr_calendar_project / vr_calendar | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryCRITICALWordPress VR Calendar <=2.3.2 - Remote Code ExecutionCVSS 9.8
WordPress VR Calendar plugin through 2.3.2 is susceptible to remote code execution. The plugin allows any user to execute arbitrary PHP functions on the site. An attacker can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected WordPress site.
Remediation
Update the WordPress VR Calendar plugin to version 2.3.3 or later to mitigate this vulnerability.
Source: ProjectDiscovery