ZeroHour

CVE-2022-3180

CVSS 3.1
9.8 critical
EPSS
9%p95
Published
()
Modified
Description

The WPGateway Plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.5. This allows unauthenticated attackers to create arbitrary malicious administrator accounts.

Vendors
wpgateway
Products
wpgateway
Ecosystems
WordPress
Weakness
CWE-290
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news