U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2022-4950

Change History

Initial Analysis by NIST 6/13/2023 2:42:34 PM

Action Type Old Value New Value
Added CPE Configuration

								
							
							
						
OR
     *cpe:2.3:a:coolplugins:cool_timeline:*:*:*:*:*:wordpress:*:* versions up to (excluding) 2.4
     *cpe:2.3:a:coolplugins:cryptocurrency_widgets:*:*:*:*:*:wordpress:*:* versions up to (excluding) 2.5.1
     *cpe:2.3:a:coolplugins:cryptocurrency_widgets_for_elementor:*:*:*:*:*:wordpress:*:* versions up to (excluding) 1.3
     *cpe:2.3:a:coolplugins:event_single_page_builder_for_the_event_calendar:*:*:*:*:*:wordpress:*:* versions up to (excluding) 1.6
     *cpe:2.3:a:coolplugins:events-notification-bar-addon:*:*:*:*:*:wordpress:*:* versions up to (excluding) 1.6
     *cpe:2.3:a:coolplugins:events_search_for_the_events_calendar:*:*:*:*:*:wordpress:*:* versions up to (excluding) 1.2
     *cpe:2.3:a:coolplugins:events_shortcodes_for_the_events_calendar:*:*:*:*:*:wordpress:*:* versions up to (excluding) 2.0
     *cpe:2.3:a:coolplugins:events_widgets_for_elementor_and_the_events_calendar:*:*:*:*:*:wordpress:*:* versions up to (excluding) 1.5
     *cpe:2.3:a:coolplugins:the_events_calendar_countdown_addon:*:*:*:*:*:wordpress:*:* versions up to (excluding) 1.4
     *cpe:2.3:a:cryptocurrency_payment_\&_donation_box_plugins:cryptocurrency_payment_\&_donation_box:*:*:*:*:*:wordpress:*:* versions up to (excluding) 1.8
Added CVSS V3.1

								
							
							
						
NIST AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Added CWE

								
							
							
						
NIST CWE-862
Changed Reference Type
https://blog.nintechnet.com/8-wordpress-plugins-fixed-high-severity-vulnerability/ No Types Assigned
https://blog.nintechnet.com/8-wordpress-plugins-fixed-high-severity-vulnerability/ Third Party Advisory
Changed Reference Type
https://plugins.trac.wordpress.org/changeset/2705076/cool-timeline/trunk/admin/timeline-addon-page/timeline-addon-page.php No Types Assigned
https://plugins.trac.wordpress.org/changeset/2705076/cool-timeline/trunk/admin/timeline-addon-page/timeline-addon-page.php Patch
Changed Reference Type
https://www.wordfence.com/threat-intel/vulnerabilities/id/f6f0fb78-ad6b-4a9e-ae1a-5793f3426379?source=cve No Types Assigned
https://www.wordfence.com/threat-intel/vulnerabilities/id/f6f0fb78-ad6b-4a9e-ae1a-5793f3426379?source=cve Broken Link, Third Party Advisory