S4E just found a high top 10 tcp port service scan
critical·Product Based Web Vulnerabilities·Updated Mar 4, 2024

CVE-2022-3982 Scanner

CVE-2022-3982 scanner - Arbitrary File Upload vulnerability in WordPress Booking Calendar

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.5k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-3982
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

The Booking calendar, Appointment Booking System WordPress plugin before 3.2.2 does not validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as PHP and achieve RCE

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Booking calendar, Appointment Booking System
AFFECTED< 3.2.2SAFE ✓≥ 3.2.2
Updated Aug 22, 2026View on NVD →
Detail

The WordPress Booking Calendar plugin is a tool designed for WordPress websites to enable booking and reservation functionalities. It is widely used by businesses and individuals to manage appointments, room bookings, or any booking type directly on their websites. Developed by wpdevart, this plugin offers an interactive calendar, a user-friendly interface, and customization options to suit various booking needs. The plugin simplifies the process of managing bookings, making it an essential tool for businesses such as hotels, rental services, and event organizers. Its vulnerability to arbitrary file uploads poses a critical security risk, potentially compromising the website's integrity and the security of its data.

CVE-2022-3982 describes a critical arbitrary file upload vulnerability found in versions of the WordPress Booking Calendar plugin before 3.2.2. This vulnerability allows attackers to upload and execute arbitrary files on the server without authentication. Such a flaw can lead to remote code execution, providing attackers with the capability to manipulate the website, access sensitive information, or further compromise the web server. As a result, websites using vulnerable versions of this plugin are at significant risk of being exploited.

The arbitrary file upload vulnerability within the WordPress Booking Calendar plugin arises due to insufficient validation of uploaded files. Attackers can exploit this flaw by crafting malicious files, such as PHP scripts, and uploading them through the plugin's functionality, bypassing any checks for file type or content. Once uploaded, these files can be executed on the server, granting attackers the ability to perform various malicious activities. The vulnerability specifically affects the wp-admin/admin-ajax.php file handling mechanism, where insufficient security measures allow unauthenticated file uploads.

Exploiting the arbitrary file upload vulnerability in the WordPress Booking Calendar plugin can have severe consequences. Attackers can gain unauthorized access to the website, execute arbitrary code, steal sensitive data, create backdoors for future access, and potentially take over the entire web server. This compromise can lead to significant financial losses, damage to reputation, and legal implications for the website owner. Additionally, the website can be used as a platform for further attacks against users or other websites.

By joining the S4E platform, you gain access to advanced security scanning capabilities that can detect vulnerabilities like CVE-2022-3982 in your digital assets. Our platform offers comprehensive vulnerability assessments, real-time alerts, and actionable recommendations to mitigate risks. Enhance your cybersecurity posture, protect your website from potential exploits, and ensure the safety of your data and users. Becoming a member of S4E enables you to leverage cutting-edge technology and expertise to maintain a secure online presence.

 

References

Solution Advice
  1. Immediately update the WordPress Booking Calendar plugin to version 3.2.2 or later.
  2. Regularly update all WordPress plugins and the core system to the latest versions to patch known vulnerabilities.
  3. Use security plugins to monitor and block malicious file uploads.
  4. Implement file upload validation checks to ensure only permitted file types can be uploaded.
  5. Regularly scan your website for vulnerabilities to detect and fix security issues promptly.
  6. Consider using a web application firewall (WAF) to provide an additional layer of security.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2022-3982 scanner - Arbitrary File Upload vulnerability in WordPress Booking Calendar S4E