← back
CVE-2022-2314observed exploitationCWE-78

VR Calendar < 2.3.2 - Unauthenticated Arbitrary Function Call

45Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 13%
from disclosure to weapon
Published on NVDAug 15
VulnCheck+504d
exploitation probability
13%top 4% of all CVEs
observed exploitation
yesVulnCheck
The VR Calendar WordPress plugin through 2.3.2 lets any user execute arbitrary PHP functions on the site.
Affected products
Unknown · VR Calendar