CVE-2022-2314

The VR Calendar WordPress plugin through 2.3.2 lets any user execute arbitrary PHP functions on the site.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:vr_calendar_project:vr_calendar:*:*:*:*:*:wordpress:*:*

History

03 Oct 2022, 14:15

Type Values Removed Values Added
Summary The VR Calendar WordPress plugin through 2.2.2 lets any user execute arbitrary PHP functions on the site. The VR Calendar WordPress plugin through 2.3.2 lets any user execute arbitrary PHP functions on the site.

16 Aug 2022, 17:44

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-78 NVD-CWE-noinfo
References (MISC) https://wpscan.com/vulnerability/b22fe77c-844e-4c24-8023-014441cc1e82 - (MISC) https://wpscan.com/vulnerability/b22fe77c-844e-4c24-8023-014441cc1e82 - Exploit, Third Party Advisory
First Time Vr Calendar Project vr Calendar
Vr Calendar Project
CPE cpe:2.3:a:vr_calendar_project:vr_calendar:*:*:*:*:*:wordpress:*:*

15 Aug 2022, 11:21

Type Values Removed Values Added
New CVE

Information

Published : 2022-08-15 11:21

Updated : 2023-12-10 14:35


NVD link : CVE-2022-2314

Mitre link : CVE-2022-2314

CVE.ORG link : CVE-2022-2314


JSON object : View

Products Affected

vr_calendar_project

  • vr_calendar
CWE
NVD-CWE-noinfo CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')