CVE-2022-4060
CRITICAL 9.8EPSS 42.7%
The User Post Gallery WordPress plugin through 2.19 does not limit what callback functions can be called by users, making it possible to any visitors to run code on sites running it.
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS
- 42.72% chance of exploitation in the next 30 days, 99th percentile
- Nuclei
- critical · CWE-94
- Published
- 2023-01-16
- Updated
- 2025-04-04
Proof-of-concept exploits (3)
- https://wpscan.com/vulnerability/8f982ebd-6fc5-452d-8280-42e027d01b1e
- devmehedi101/wordpress-exploit0★ · 2023-11-20
- securi3ytalent/wordpress-exploit0★ · 2023-11-20