Cool Plugins (Various Versions) - Arbitrary Plugin Installation and Activation
Affected versions: *-1.3.1; *-1.1; *-2.3.3; *-1.7; *-1.1.3; [*, 1.3); *-1.5; *-1.9.4
Vulnerability type: CWE-862 Missing Authorization
Affected software, patched versions and attribution
Several WordPress plugins developed by Cool Plugins are vulnerable to arbitrary plugin installation and activation that can lead to remote code execution by authenticated attackers with minimal permissions, such as a subscriber.
Event Countdown for The Events Calendar
Affected versions: *-1.3.1
Patched versions: 1.4
The Events Calendar Events Notification Bar Addon
Affected versions: *-1.1
Patched versions: 1.6
Cool Timeline (Horizontal & Vertical Timeline)
Affected versions: *-2.3.3
Patched versions: 2.4
Cryptocurrency Donation Box – Bitcoin & Crypto Donations
Affected versions: *-1.7
Patched versions: 1.8
Events Search For The Events Calendar
Affected versions: *-1.1.3
Patched versions: 1.2
Cryptocurrency Widgets For Elementor
Affected versions: [*, 1.3)
Patched versions: 1.3
Event Single Page Builder For The Events Calendar
Affected versions: *-1.5
Patched versions: 1.6
Events Shortcodes For The Events Calendar
Affected versions: *-1.9.4
Patched versions: 2.0
Cryptocurrency Widgets – Price Ticker & Coins List
Affected versions: *-2.4
Patched versions: 2.5.1
Events Widgets For Elementor And The Events Calendar
Affected versions: *-1.4.2
Patched versions: 1.5
Researcher credit: Jerome Bruandet
Applicable copyright and licence notices
This record contains material that is subject to copyright
Copyright 2012-2026 Defiant Inc.
Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.
This record contains material that is subject to copyright
Copyright 1999-2026 The MITRE Corporation
CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.
- Published
- April 4, 2022
- CVSS
- 8.8