VR Calendar < 2.3.2 - Unauthenticated Arbitrary Function Call
45Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 17%
from disclosure to weapon
Published on NVDAug 15
VulnCheck+504d
exploitation probability
17%top 3% of all CVEs
observed exploitation
yesVulnCheck
The VR Calendar WordPress plugin through 2.3.2 lets any user execute arbitrary PHP functions on the site.
Affected products
Unknown · VR Calendar