← back
CVE-2022-4060criticalobserved exploitation

User Post Gallery <= 2.19 - Unauthenticated RCE

97Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actcvss 9.8epss 43%
from disclosure to weapon242 days
Published on NVDJan 16
1st PoC+242d
VulnCheckDec 26
exploitation probability
43%top 1% of all CVEs
observed exploitation
yesVulnCheck
3 public exploit(s)
The User Post Gallery WordPress plugin through 2.19 does not limit what callback functions can be called by users, making it possible to any visitors to run code on sites running it.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.