Back to search
CVE-2022-3982
Published: Dec 12, 2022
Modified: Apr 22, 2025
PUBLISHED
Description
The Booking calendar, Appointment Booking System WordPress plugin before 3.2.2 does not validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as PHP and achieve RCE
| Vendor | Product | Versions |
|---|---|---|
Unknown | Booking calendar, Appointment Booking System | affected 0 - < 3.2.2 |
References
https://wpscan.com/vulnerability/4d91f3e1-4de9-46c1-b5ba-cc55b7726867
exploit
vdb-entry
technical-description
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now