Several WordPress plugins developed by Cool Plugins are vulnerable to arbitrary plugin installation and activation that can lead to remote code execution by authenticated attackers with minimal permissions, such as a subscriber.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Cool Timeline Plugin | cool-timeline-plugin-cve-2022-4950 | May 15, 2025 | Apr 4, 2022 | |
| Countdown For The Events Calendar Plugin | countdown-for-the-events-calendar-plugin-cve-2022-4950 | May 15, 2025 | Apr 4, 2022 | |
| Cryptocurrency Donation Box Plugin | cryptocurrency-donation-box-plugin-cve-2022-4950 | May 15, 2025 | Apr 4, 2022 | |
| Cryptocurrency Price Ticker Widget Plugin | cryptocurrency-price-ticker-widget-plugin-cve-2022-4950 | May 15, 2025 | Apr 4, 2022 | |
| Cryptocurrency Widgets For Elementor Plugin | cryptocurrency-widgets-for-elementor-plugin-cve-2022-4950 | May 15, 2025 | Apr 4, 2022 | |
| Event Page Templates Addon For The Events Calendar Plugin | event-page-templates-addon-for-the-events-calendar-plugin-cve-2022-4950 | May 15, 2025 | Apr 4, 2022 | |
| Events Notification Bar Addon Plugin | events-notification-bar-addon-plugin-cve-2022-4950 | May 15, 2025 | Apr 4, 2022 | |
| Events Search Addon For The Events Calendar Plugin | events-search-addon-for-the-events-calendar-plugin-cve-2022-4950 | May 15, 2025 | Apr 4, 2022 | |
| Events Widgets For Elementor And The Events Calendar Plugin | events-widgets-for-elementor-and-the-events-calendar-plugin-cve-2022-4950 | May 15, 2025 | Apr 4, 2022 | |
| Template Events Calendar Plugin | template-events-calendar-plugin-cve-2022-4950 | May 15, 2025 | Apr 4, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub