ZeroHour

CVE-2022-4060

PoC
CVSS 3.1
9.8 critical
EPSS
43%p99
Published
()
Modified
Description

The User Post Gallery WordPress plugin through 2.19 does not limit what callback functions can be called by users, making it possible to any visitors to run code on sites running it.

Vendors
odude
Products
user post gallery
Ecosystems
WordPress
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.