ZeroHour

CVE-2022-24664

CVSS 3.1
8.8 high
EPSS
2%p75
Published
()
Modified
Description

PHP Everywhere <= 2.0.3 included functionality that allowed execution of PHP Code Snippets via WordPress metaboxes, which could be used by any user able to edit posts.

Vendors
php everywhere project
Products
php everywhere
Ecosystems
WordPress
Weakness
CWE-94
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news