nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-24664 CVE-2022-24664
CRITICAL
Remote Code Execution by by Contributor+ users via WordPress metabox
Record summary
CVE-2022-24664 has a selected CVSS score of 9.9 (critical).
Description
PHP Everywhere <= 2.0.3 included functionality that allowed execution of PHP Code Snippets via WordPress metaboxes, which could be used by any user able to edit posts.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jul 25, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 31, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
PHP EverywhereBrowse Alexander Fuchs / PHP Everywhere | CVE List | 2.0.3 to ≤ 2.0.3 | affected |
php_everywhereBrowse php_everywhere_project / php_everywhere | VulnCheck | Version data not supplied | |
References
2wordfence.com
https://www.wordfence.com/blog/2022/02/critical-vulnerabilities-in-php-everywhere-allow-remote-code-execution