Record summary

CVE-2022-24664 has a selected CVSS score of 9.9 (critical).

Description

PHP Everywhere <= 2.0.3 included functionality that allowed execution of PHP Code Snippets via WordPress metaboxes, which could be used by any user able to edit posts.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jul 25, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 31, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE List2.0.3 to ≤ 2.0.3affected
VulnCheckVersion data not supplied

References

2