CVE-2022-4060
User Post Gallery <= 2.19 - Unauthenticated RCE
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
The User Post Gallery WordPress plugin through 2.19 does not limit what callback functions can be called by users, making it possible to any visitors to run code on sites running it.
El complemento User Post Gallery de WordPress hasta la versión 2.19 no limita las funciones de devolución de llamada que pueden invocar los usuarios, lo que permite a cualquier visitante ejecutar código en los sitios que lo ejecutan.
The User Post Gallery - UPG plugin for WordPress is vulnerable to authorization bypass which leads to remote command execution due to the use of a nopriv AJAX action and user supplied function calls and parameters in versions up to, and including 2.19. This makes it possible for unauthenticated attackers to call arbitrary PHP functions and perform actions like adding new files that can be webshells and updating the site's options to allow anyone to register as an administrator.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-11-18 CVE Reserved
- 2022-12-26 CVE Published
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://github.com/im-hanzou/UPGer | 2024-11-21 | |
https://wpscan.com/vulnerability/8f982ebd-6fc5-452d-8280-42e027d01b1e | 2024-08-03 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Odude Search vendor "Odude" | User Post Gallery Search vendor "Odude" for product "User Post Gallery" | <= 2.19 Search vendor "Odude" for product "User Post Gallery" and version " <= 2.19" | wordpress |
Affected
|