Remote Code Execution by by Contributor+ users via WordPress metabox
CVE-2022-24664
9.9CRITICAL
What is CVE-2022-24664?
PHP Everywhere <= 2.0.3 included functionality that allowed execution of PHP Code Snippets via WordPress metaboxes, which could be used by any user able to edit posts.
Affected Version(s)
PHP Everywhere WordPress 2.0.3