CVE-2022-4950
Several WordPress plugins developed by Cool Plugins are vulnerable to arbitrary plugin installation and activation that can lead to remote code execution by authenticated attackers with minimal permissions, such as a subscriber.
Published:Jun 7, 2023
Last Modified:Apr 8, 2026
EPS:Jun 7, 2023
EPSS Score:0.05417
CVSS Score:8.8
Affected Products
Vendor
Product
Action
Vendor
Coolplugins
Product
Cool Timeline
Coolplugins
Cool Timeline
Vendor
Coolplugins
Product
Cryptocurrency Widgets
Coolplugins
Cryptocurrency Widgets
Vendor
Coolplugins
Product
Cryptocurrency Widgets For Elementor
Coolplugins
Cryptocurrency Widgets For Elementor
Vendor
Coolplugins
Product
Event Single Page Builder For The Event Calendar
Coolplugins
Event Single Page Builder For The Event Calendar
Vendor
Coolplugins
Product
Events-notification-bar-addon
Coolplugins
Events-notification-bar-addon
Vendor
Coolplugins
Product
Events Search For The Events Calendar
Coolplugins
Events Search For The Events Calendar
Vendor
Coolplugins
Product
Events Shortcodes For The Events Calendar
Coolplugins
Events Shortcodes For The Events Calendar
Vendor
Coolplugins
Product
Events Widgets For Elementor And The Events Calendar
Coolplugins
Events Widgets For Elementor And The Events Calendar
Vendor
Coolplugins
Product
The Events Calendar Countdown Addon
Coolplugins
The Events Calendar Countdown Addon
Vendor
Cryptocurrency Payment \& Donation Box Plugins
Product
Cryptocurrency Payment \& Donation Box
Cryptocurrency Payment \& Donation Box Plugins
Cryptocurrency Payment \& Donation Box
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
