PHP Everywhere <= 2.0.2 - Cross-Site Request Forgery
high
The PHP Everywhere plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.2. This makes it possible for unauthenticated attackers to conduct unspecified potential attacks via forged request granted they can trick a site administrator into performing an action such as clic...
- CVSS:
- 8.8
- Affected:
- up to 2.0.2
- Fixed in:
- 2.0.3
- Disclosed:
- Jan 13, 2022
CVE-2021-23227 on NVD →
PHP Everywhere <= 2.0.3 - Remote Code Execution by Contributor+ users via gutenberg block
critical
PHP Everywhere <= 2.0.3 included functionality that allowed execution of PHP Code Snippets via a WordPress gutenberg block by any user able to edit posts.
- CVSS:
- 9.9
- Affected:
- up to 2.0.3
- Fixed in:
- 3.0.0
- Disclosed:
- Jan 4, 2022
CVE-2022-24665 on NVD →
PHP Everywhere <= 2.0.3 - Authenticated (Contributor+) Remote Code Execution via Metabox
critical
PHP Everywhere <= 2.0.3 included functionality that allowed execution of PHP Code Snippets via WordPress metaboxes, which could be used by any user able to edit posts.
- CVSS:
- 9.9
- Affected:
- up to 2.0.3
- Fixed in:
- 3.0.0
- Disclosed:
- Jan 4, 2022
CVE-2022-24664 on NVD →
PHP Everywhere <= 2.0.3 - Remote Code Execution by Subscriber+ users via shortcode
critical
PHP Everywhere <= 2.0.3 included functionality that allowed execution of PHP Code Snippets via WordPress shortcodes, which can be used by any authenticated user.
- CVSS:
- 9.9
- Affected:
- up to 2.0.3
- Fixed in:
- 3.0.0
- Disclosed:
- Jan 4, 2022
CVE-2022-24663 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database