← Back to browse · API

CVE-2022-24664

Severity
CRITICAL
CVSS
9.9
EPSS
0.0165
Risk score
40.18
CISA KEV
No
PoC
No
Published
2022-02-16
Modified
2025-01-31
First seen
2026-08-07
Aliases
EUVD-2022-29539, GHSA-32FP-MQG5-24WV
Products
Alexander Fuchs:PHP Everywhere 2.0.3 ≤2.0.3
Sources
euvd EUVD-2022-29539

Description

PHP Everywhere <= 2.0.3 included functionality that allowed execution of PHP Code Snippets via WordPress metaboxes, which could be used by any user able to edit posts.

References