CVE-2022-1952 is a critical arbitrary file upload vulnerability affecting the Free Booking Plugin for Hotels, Restaurant and Car Rental WordPress plugin prior to version 1.1.16. This flaw, due to insufficient input validation, allows unauthenticated attackers to upload malicious files and achieve remote code execution. With a CVSS score of 9.8 (CRITICAL) and an EPSS score indicating high exploitability, this vulnerability poses a significant risk due to its network-based attack vector, low complexity, and complete compromise potential. While there is no evidence of active exploitation or Metasploit modules, Nuclei templates exist, and despite its severity, there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.1.16CPE matchmatch criteria | cpe:2.3:a:syntacticsinc:easync:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.