VYPR
Critical severity9.8NVD Advisory· Published Feb 11, 2025· Updated Jun 17, 2026

CVE-2022-3180

CVE-2022-3180

Description

The WPGateway Plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.5. This allows unauthenticated attackers to create arbitrary malicious administrator accounts.

Affected products

4
  • cpe:2.3:a:wpgateway:wpgateway:*:*:*:*:*:wordpress:*:*
    Range: <=3.5
  • WordPress/WPGatewayllm-fuzzy2 versions
    <=3.5+ 1 more
    • (no CPE)range: <=3.5
    • (no CPE)
  • Jack Hopman/WPGatewayv5
    Range: *

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.