VR Calendar < 2.3.2 - Unauthenticated Arbitrary Function Call
45Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 13%
from disclosure to weapon
Published on NVDAug 15
VulnCheck+504d
exploitation probability
13%top 4% of all CVEs
observed exploitation
yesVulnCheck
The VR Calendar WordPress plugin through 2.3.2 lets any user execute arbitrary PHP functions on the site.
Affected products
Unknown · VR Calendar