CVE-2022-3180
CRITICALCVSS 9.8/10EPSS 8.84%
Last modified
CVE-2022-3180 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. The WPGateway Plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.5. This allows unauthenticated attackers to create arbitrary malicious administrator accounts.. EPSS estimates a 8.84% chance of exploitation in the next 30 days.
Description
The WPGateway Plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.5. This allows unauthenticated attackers to create arbitrary malicious administrator accounts.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Wpgateway | Wpgateway | <= 3.5 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2022-3180?
The WPGateway Plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.5. This allows unauthenticated attackers to create arbitrary malicious administrator accounts.
How severe is CVE-2022-3180?
CVE-2022-3180 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 8.84% probability of exploitation in the next 30 days.
How do I fix CVE-2022-3180?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-31793do_request in request.c in muhttpd before 1.1.7 allows remot…7.5
- CVE-2022-31794An issue was discovered on Fujitsu ETERNUS CentricStor CS800…9.8
- CVE-2022-31795An issue was discovered on Fujitsu ETERNUS CentricStor CS800…9.8
- CVE-2022-31796libjpeg 1.63 has a heap-based buffer over-read in Hierarchic…6.5
- CVE-2022-31798Nortek Linear eMerge E3-Series 0.32-07p devices are vulnerab…6.1
- CVE-2022-31799Bottle before 0.12.20 mishandles errors during early request…9.8
- CVE-2022-31800An unauthenticated, remote attacker could upload malicious l…9.8
- CVE-2022-31801An unauthenticated, remote attacker could upload malicious l…9.8
- CVE-2022-31802In CODESYS Gateway Server V2 for versions prior to V2.3.9.38…9.8
- CVE-2022-31803In CODESYS Gateway Server V2 an insufficient check for the a…5.3
- CVE-2022-31804The CODESYS Gateway Server V2 does not verifiy that the size…7.5
- CVE-2022-31805In the CODESYS Development System multiple components in mul…7.5
Are you affected by CVE-2022-3180?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
