CVE-2022-3180

The WPGateway Plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.5. This allows unauthenticated attackers to create arbitrary malicious administrator accounts.
Configurations

Configuration 1 (hide)

cpe:2.3:a:wpgateway:wpgateway:*:*:*:*:*:wordpress:*:*

History

05 Jun 2025, 14:24

Type Values Removed Values Added
CPE cpe:2.3:a:wpgateway:wpgateway:*:*:*:*:*:wordpress:*:*
References () https://www.wordfence.com/blog/2022/09/psa-zero-day-vulnerability-in-wpgateway-actively-exploited-in-the-wild/ - () https://www.wordfence.com/blog/2022/09/psa-zero-day-vulnerability-in-wpgateway-actively-exploited-in-the-wild/ - Third Party Advisory
References () https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpgateway/wpgateway-35-unauthenticated-privilege-escalation - () https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpgateway/wpgateway-35-unauthenticated-privilege-escalation - Third Party Advisory
First Time Wpgateway wpgateway
Wpgateway

14 Mar 2025, 17:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

18 Feb 2025, 18:15

Type Values Removed Values Added
Summary
  • (es) El complemento WPGateway para WordPress es vulnerable a la escalada de privilegios en versiones hasta la 3.5 y incluida. Esto permite que atacantes no autenticados creen cuentas de administrador maliciosas arbitrarias.
CVSS v2 : unknown
v3 : 9.8
v2 : unknown
v3 : unknown

12 Feb 2025, 15:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

11 Feb 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-11 22:15

Updated : 2025-06-05 14:24


NVD link : CVE-2022-3180

Mitre link : CVE-2022-3180

CVE.ORG link : CVE-2022-3180


JSON object : View

Products Affected

wpgateway

  • wpgateway
CWE
CWE-290

Authentication Bypass by Spoofing