← Back to browse · API

CVE-2022-3180

Severity
CRITICAL
CVSS
9.8
EPSS
0.0921
Risk score
42.42
CISA KEV
No
PoC
No
Published
2025-02-11
Modified
2025-03-14
First seen
2026-08-07
Aliases
EUVD-2022-42597, GHSA-7XF9-6RPX-2C4R
Products
Jack Hopman:WPGateway * ≤3.5
Sources
euvd EUVD-2022-42597

Description

The WPGateway Plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.5. This allows unauthenticated attackers to create arbitrary malicious administrator accounts.

References