8.8
CVSSv3

CVE-2022-24664

Published: 16/02/2022 Updated: 24/02/2022
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N

Vulnerability Summary

PHP Everywhere <= 2.0.3 included functionality that allowed execution of PHP Code Snippets via WordPress metaboxes, which could be used by any user able to edit posts.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

php everywhere project php everywhere

Exploits

PHP Everywhere versions 203 and below suffer from multiple remote code execution vulnerabilities ...