CVE-2022-3982
PoC —CVSS 3.1
9.8 critical
EPSS
4%p91
Published
()
Modified
Description
The Booking calendar, Appointment Booking System WordPress plugin before 3.2.2 does not validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as PHP and achieve RCE
- Vendors
- wpdevart
- Products
- booking calendar
- Ecosystems
- WordPress
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.