← Back to browse · API

CVE-2022-24665

Severity
CRITICAL
CVSS
9.9
EPSS
0.026
Risk score
40.51
CISA KEV
No
PoC
No
Published
2022-02-16
Modified
2025-01-31
First seen
2026-08-07
Aliases
EUVD-2022-29540, GHSA-6GMW-4W3R-GWC2
Products
Alexander Fuchs:PHP Everywhere 2.0.3 ≤2.0.3
Sources
euvd EUVD-2022-29540

Description

PHP Everywhere <= 2.0.3 included functionality that allowed execution of PHP Code Snippets via a WordPress gutenberg block by any user able to edit posts.

References