QID 150493
Date Published: 2022-03-30
QID 150493: WordPress PHP Everywhere Plugin : Remote Code Execution Vulnerabilities (CVE-2022-24663,CVE-2022-24664,CVE-2022-24665)
PHP Everywhere is a WordPress plugin. This plugin enables PHP code everywhere in your WordPress installation.
Affected versions of PHP Everywhere contains multiple vulnerabilities:
CVE-2022-24663: PHP Everywhere included a functionality that allowed the execution of PHP Code Snippets via WordPress shortcodes, which can be used by any authenticated user.
CVE-2022-24664: PHP Everywhere included a functionality that allowed the execution of PHP Code Snippets via WordPress metaboxes, which could be used by any user able to edit posts.
CVE-2022-24665: PHP Everywhere included a functionality that allowed execution of PHP Code Snippets via a WordPress gutenberg block by any user able to edit posts.
Affected Versions:
PHP Everywhere versions 2.0.3 and prior.
QID Detection Logic:
This QID sends an HTTP GET request and retrieves a vulnerable version of the PHP Everywhere plugin running on the target application.
Successful exploitation of the vulnerability will allow remote attacker to execute arbitrary code on the target system.
CVEs related to QID 150493
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| PHP Everywhere |
|
||
| Wordfence |
|