cve-2022-3982

CRITICAL CVSS 9.8 opencve
Description

The Booking calendar, Appointment Booking System WordPress plugin before 3.2.2 does not validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as PHP and achieve RCE

Timeline
Published
2022-12-12 18:15 UTC
Last Modified
2026-06-17
CVSS Details

CVSS details not available.

Affected Products

No product information available.

CVSS metrics
Version Base Severity Vector Exploitability Impact Source
3.1 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H nvd
3.1 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H opencve
3.1 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H vulnrichment
References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "cve": "CVE-2022-3982",
  "epss": {
    "score": 0.0454
  },
  "mitre": {
    "cpes": [],
    "created": "2022-12-12T17:54:47.850000+00:00",
    "description": "The Booking calendar, Appointment Booking System WordPress plugin before 3.2.2 does not validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as PHP and achieve RCE",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {},
      "cvssV4_0": {}
    },
    "mitre_repo_path": "cves/2022/3xxx/CVE-2022-3982.json",
    "references": [
      "https://wpscan.com/vulnerability/4d91f3e1-4de9-46c1-b5ba-cc55b7726867"
    ],
    "title": "Booking Calendar < 3.2.2 - Unauthenticated Arbitrary File Upload",
    "updated": "2025-04-22T14:52:56.748000+00:00",
    "vendors": [],
    "weaknesses": []
  },
  "nvd": {
    "cpes": [
      "cpe:2.3:a:wpdevart:booking_calendar:*:*:*:*:*:wordpress:*:*"
    ],
    "created": "2022-12-12T18:15:12.487000+00:00",
    "description": "The Booking calendar, Appointment Booking System WordPress plugin before 3.2.2 does not validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as PHP and achieve RCE",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {
        "score": 9.8,
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "cvssV4_0": {}
    },
    "nvd_repo_path": "2022/CVE-2022-3982.json",
    "references": [
      "https://wpscan.com/vulnerability/4d91f3e1-4de9-46c1-b5ba-cc55b7726867"
    ],
    "title": null,
    "updated": "2026-06-17T05:00:42.480000+00:00",
    "vendors": [
      "wpdevart",
      "wpdevart$PRODUCT$booking_calendar"
    ],
    "weaknesses": []
  },
  "opencve": {
    "changes": [
      {
        "created": "2025-04-22T15:15:00+00:00",
        "data": [
          {
            "details": {
              "added": {
                "ssvc": {
                  "options": {
                    "Automatable": "yes",
                    "Exploitation": "poc",
                    "Technical Impact": "total"
                  },
                  "version": "2.0.3"
                }
              },
              "removed": {},
              "updated": {}
            },
            "type": "metrics"
          }
        ],
        "id": "e7b0e1d7-3a89-45ce-ab91-c2b20569af11"
      }
    ],
    "cpes": {
      "data": [
        "cpe:2.3:a:wpdevart:booking_calendar:*:*:*:*:*:wordpress:*:*"
      ],
      "providers": [
        "nvd"
      ]
    },
    "created": {
      "data": "2022-12-12T17:54:47.850000+00:00",
      "provider": "mitre"
    },
    "description": {
      "data": "The Booking calendar, Appointment Booking System WordPress plugin before 3.2.2 does not validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as PHP and achieve RCE",
      "provider": "mitre"
    },
    "metrics": {
      "cvssV2_0": {
        "data": {},
        "provider": null
      },
      "cvssV3_0": {
        "data": {},
        "provider": null
      },
      "cvssV3_1": {
        "data": {
          "score": 9.8,
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        "provider": "vulnrichment"
      },
      "cvssV4_0": {
        "data": {},
        "provider": null
      },
      "epss": {
        "data": {
          "score": 0.0454
        },
        "provider": "first"
      },
      "kev": {
        "data": {},
        "provider": null
      },
      "ssvc": {
        "data": {
          "options": {
            "Automatable": "yes",
            "Exploitation": "poc",
            "Technical Impact": "total"
          },
          "version": "2.0.3"
        },
        "provider": "vulnrichment"
      },
      "threat_severity": {
        "data": null,
        "provider": null
      }
    },
    "references": {
      "data": [
        "https://wpscan.com/vulnerability/4d91f3e1-4de9-46c1-b5ba-cc55b7726867"
      ],
      "providers": [
        "mitre",
        "nvd"
      ]
    },
    "title": {
      "data": "Booking Calendar < 3.2.2 - Unauthenticated Arbitrary File Upload",
      "provider": "mitre"
    },
    "updated": {
      "data": "2025-04-22T15:16:02.157000+00:00",
      "provider": "nvd"
    },
    "vendors": {
      "data": [
        "wpdevart",
        "wpdevart$PRODUCT$booking_calendar"
      ],
      "providers": [
        "nvd"
      ]
    },
    "weaknesses": {
      "data": [],
      "providers": []
    }
  },
  "vulnrichment": {
    "cpes": [],
    "created": "2022-12-12T17:54:47.850000+00:00",
    "description": "The Booking calendar, Appointment Booking System WordPress plugin before 3.2.2 does not validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as PHP and achieve RCE",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {
        "score": 9.8,
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "cvssV4_0": {},
      "kev": {},
      "ssvc": {
        "options": {
          "Automatable": "yes",
          "Exploitation": "poc",
          "Technical Impact": "total"
        },
        "version": "2.0.3"
      }
    },
    "references": [],
    "title": "Booking Calendar < 3.2.2 - Unauthenticated Arbitrary File Upload",
    "updated": "2025-04-22T14:52:47.713000+00:00",
    "vendors": [],
    "vulnrichment_repo_path": "2022/3xxx/CVE-2022-3982.json",
    "weaknesses": []
  }
}
Enrichment data
View JSON API Download JSON