CVE Database
/

CVE-2022-4950

Back to search

CVE-2022-4950

Published: Jun 7, 2023

Modified: Apr 8, 2026

PUBLISHED

CVSS v3.1

8.8

HIGH

Description

Several WordPress plugins developed by Cool Plugins are vulnerable to arbitrary plugin installation and activation that can lead to remote code execution by authenticated attackers with minimal permissions, such as a subscriber.

VendorProductVersions

narinder-singh

The Events Calendar Events Notification Bar Addon

affected
0 - <= 1.1

narinder-singh

Events Search For The Events Calendar

affected
0 - <= 1.1.3

coolplugins

Cryptocurrency Widgets For Elementor

affected
0 - < 1.3

narinder-singh

Event Countdown for The Events Calendar

affected
0 - <= 1.3.1

coolplugins

Events Widgets For Elementor And The Events Calendar

affected
0 - <= 1.4.2

narinder-singh

Event Single Page Builder For The Events Calendar

affected
0 - <= 1.5

blackworks1

Cryptocurrency Donation Box – Bitcoin & Crypto Donations

affected
0 - <= 1.7

narinder-singh

Events Shortcodes For The Events Calendar

affected
0 - <= 1.9.4

narinder-singh

Cool Timeline (Horizontal & Vertical Timeline)

affected
0 - <= 2.3.3

narinder-singh

Cryptocurrency Widgets – Price Ticker & Coins List

affected
0 - <= 2.4

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector

Network

Attack Complexity

Low

Privileges Required

Low

User Interaction

None

Scope

Unchanged

Confidentiality

High

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now