CVE-2022-4950: Coolplugins Cool Timeline
High severity, CVSS 8.8. EPSS: 1.4% chance of exploitation in the next 30 days.
Several WordPress plugins developed by Cool Plugins are vulnerable to arbitrary plugin installation and activation that can lead to remote code execution by authenticated attackers with minimal permissions, such as a subscriber.
Affected products
- Coolplugins Cool Timeline: before 2.4 (fixed in 2.4)
- Coolplugins Cryptocurrency Widgets: before 2.5.1 (fixed in 2.5.1)
- Coolplugins Cryptocurrency Widgets For Elementor: before 1.3 (fixed in 1.3)
- Coolplugins Event Single Page Builder For The Event Calendar: before 1.6 (fixed in 1.6)
- Coolplugins Events-Notification-Bar-Addon: before 1.6 (fixed in 1.6)
- Coolplugins Events Search For The Events Calendar: before 1.2 (fixed in 1.2)
- Coolplugins Events Shortcodes For The Events Calendar: before 2.0 (fixed in 2.0)
- Coolplugins Events Widgets For Elementor And The Events Calendar: before 1.5 (fixed in 1.5)
- Coolplugins The Events Calendar Countdown Addon: before 1.4 (fixed in 1.4)
- Cryptocurrency Payment & Donation Box Plugins Cryptocurrency Payment & Donation Box: before 1.8 (fixed in 1.8)
Published 2023-06-07. Last modified 2026-06-17.