← Back to browse · API

CVE-2022-24663

Severity
CRITICAL
CVSS
9.9
EPSS
0.02047
Risk score
40.32
CISA KEV
No
PoC
No
Published
2022-02-16
Modified
2025-01-31
First seen
2026-08-07
Aliases
EUVD-2022-29538, GHSA-QJVJ-J3F4-JVJR
Products
Alexander Fuchs:PHP Everywhere 2.0.3 ≤2.0.3
Sources
euvd EUVD-2022-29538

Description

PHP Everywhere <= 2.0.3 included functionality that allowed execution of PHP Code Snippets via WordPress shortcodes, which can be used by any authenticated user.

References