CVE Feed

    Dashboard / CVE / CVE-2022-2441

    CVE-2022-2441

    The ImageMagick Engine plugin for WordPress is vulnerable to remote code execution via the 'cli_path' parameter in versions up to, and including 1.7.5. This makes it possible for unauthenticated users to run arbitrary commands leading to remote command execution, granted they can trick a site administrator into performing an action such as clicking on a link. This makes it possible for an attacker to create and or modify files hosted on the server which can easily grant attackers backdoor access to the affected server.

    Published:Oct 20, 2023
    Last Modified:Apr 8, 2026
    EPS:Oct 20, 2023
    EPSS Score:0.01898
    CVSS Score:8.8

    Affected Products

    Vendor
    Orangelab
    Product
    Imagemagick Engine

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High