CVE-2022-3180

The WPGateway Plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.5. This allows unauthenticated attackers to create arbitrary malicious administrator accounts.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

cpe:2.3:a:wpgateway:wpgateway:*:*:*:*:*:wordpress:*:*

History

05 Jun 2025, 14:24

Type Values Removed Values Added
First Time Wpgateway wpgateway
Wpgateway
References () https://www.wordfence.com/blog/2022/09/psa-zero-day-vulnerability-in-wpgateway-actively-exploited-in-the-wild/ - () https://www.wordfence.com/blog/2022/09/psa-zero-day-vulnerability-in-wpgateway-actively-exploited-in-the-wild/ - Third Party Advisory
References () https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpgateway/wpgateway-35-unauthenticated-privilege-escalation - () https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpgateway/wpgateway-35-unauthenticated-privilege-escalation - Third Party Advisory
CPE cpe:2.3:a:wpgateway:wpgateway:*:*:*:*:*:wordpress:*:*
CWE CWE-290

14 Mar 2025, 17:15

Type Values Removed Values Added
CWE CWE-290

11 Feb 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-11 22:15

Updated : 2025-06-05 14:24


NVD link : CVE-2022-3180

Mitre link : CVE-2022-3180


JSON object : View

Products Affected

wpgateway

  • wpgateway
CWE
CWE-290

Authentication Bypass by Spoofing