First published: Mon Dec 12 2022(Updated: )
The Booking calendar, Appointment Booking System WordPress plugin before 3.2.2 does not validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as PHP and achieve RCE
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Wpdevart Booking Calendar | <3.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2022-3982.
The severity of CVE-2022-3982 is critical.
The Booking calendar Appointment Booking System WordPress plugin before version 3.2.2 is affected by CVE-2022-3982.
CVE-2022-3982 allows unauthenticated users to upload arbitrary files, such as PHP, and potentially achieve remote code execution on the affected software.
Yes, updating the Booking calendar Appointment Booking System WordPress plugin to version 3.2.2 or higher will fix CVE-2022-3982.