peter bassill · operator
$ cve CVE-2022-4060 JSON

CVE-2022-4060

9.8
CRITICAL · CVSS 3.1 · EPSS 42.7% (pctl 99)

Patch early

EPSS 42.7% — above the 10% action threshold.

Description

The User Post Gallery WordPress plugin through 2.19 does not limit what callback functions can be called by users, making it possible to any visitors to run code on sites running it.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS42.72% — more likely to be exploited than 99% of all CVEs
On CISA KEVno
Public exploitnone known
Published2023-01-16
Last modified2026-06-17

Affected (1)

VendorProduct
odudeuser post gallery

References

→ the Explorer  ·  watch your stack  ·  NVD