Vulnerability Details CVE-2022-24664
PHP Everywhere <= 2.0.3 included functionality that allowed execution of PHP Code Snippets via WordPress metaboxes, which could be used by any user able to edit posts.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.015
EPSS Ranking 80.1%
CVSS Severity
CVSS v3 Score 9.9
CVSS v2 Score 4.0
Products affected by CVE-2022-24664
-
cpe:2.3:a:php_everywhere_project:php_everywhere:-
-
cpe:2.3:a:php_everywhere_project:php_everywhere:1.0
-
cpe:2.3:a:php_everywhere_project:php_everywhere:1.1
-
cpe:2.3:a:php_everywhere_project:php_everywhere:1.1.2
-
cpe:2.3:a:php_everywhere_project:php_everywhere:1.2
-
cpe:2.3:a:php_everywhere_project:php_everywhere:1.2.3
-
cpe:2.3:a:php_everywhere_project:php_everywhere:1.2.4
-
cpe:2.3:a:php_everywhere_project:php_everywhere:1.2.5
-
cpe:2.3:a:php_everywhere_project:php_everywhere:1.3
-
cpe:2.3:a:php_everywhere_project:php_everywhere:1.4
-
cpe:2.3:a:php_everywhere_project:php_everywhere:1.4.1
-
cpe:2.3:a:php_everywhere_project:php_everywhere:1.4.2
-
cpe:2.3:a:php_everywhere_project:php_everywhere:1.4.3
-
cpe:2.3:a:php_everywhere_project:php_everywhere:1.4.4
-
cpe:2.3:a:php_everywhere_project:php_everywhere:1.4.5
-
cpe:2.3:a:php_everywhere_project:php_everywhere:2.0.0
-
cpe:2.3:a:php_everywhere_project:php_everywhere:2.0.1
-
cpe:2.3:a:php_everywhere_project:php_everywhere:2.0.2
-
cpe:2.3:a:php_everywhere_project:php_everywhere:2.0.3