CVE-2022-3180 is a critical privilege escalation vulnerability affecting the WPGateway Plugin for WordPress, versions up to and including 3.5. This flaw allows unauthenticated attackers to create arbitrary malicious administrator accounts on affected sites. With a CVSS score of 9.8 (CRITICAL), it presents a severe risk due to its network-based attack vector, low attack complexity, and complete compromise potential across confidentiality, integrity, and availability. Despite the absence of public exploit tools, this vulnerability is actively being exploited in the wild, as confirmed by multiple media reports and its presence on the "Hot List: Active."
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.5CPE matchmatch criteria | cpe:2.3:a:wpgateway:wpgateway:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.