PoC Index

CVE-2022-3982

CRITICAL 9.8EPSS 4.5%

The Booking calendar, Appointment Booking System WordPress plugin before 3.2.2 does not validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as PHP and achieve RCE

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
4.49% chance of exploitation in the next 30 days, 91th percentile
Nuclei
critical · CWE-434
Published
2022-12-12
Updated
2025-04-22

Proof-of-concept exploits (1)

Nuclei templates (1)

Exploit collections (1)

References

Related