CVE-2022-38067: WordPress Event Calendar – Calendar plugin <= 1.4.6 - Unauthenticated Event Deletion vulnerability
Published Sep 9, 2022
·Updated
Unauthenticated Event Deletion vulnerability in Totalsoft Event Calendar – Calendar plugin <= 1.4.6 at WordPress.
Affected Software
1 affected component
Total-Soft Event Calendar Wordpress<=1.4.6
Event History
Sep 9, 2022
CVE Published
via MITRE·02:39 PM
Data Sourced
via MITRE·02:39 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-38067?
The severity of CVE-2022-38067 is medium with a severity value of 5.3.
2
What is the affected software for CVE-2022-38067?
The affected software for CVE-2022-38067 is Totalsoft Event Calendar – Calendar plugin version up to and including 1.4.6 at WordPress.
3
How can an attacker exploit CVE-2022-38067?
An attacker can exploit CVE-2022-38067 by performing unauthenticated event deletion in the Totalsoft Event Calendar – Calendar plugin.
4
Is there a patch or fix available for CVE-2022-38067?
Yes, a patch or fix is available for CVE-2022-38067. Please refer to the following link for more information: [link]
5
What is the CWE ID for CVE-2022-38067?
The CWE ID for CVE-2022-38067 is 264.