S4E just found a medium-severity finding from cookies without secure attribute security misconfiguration scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-4060 Scanner

Detects 'Remote Code Execution (RCE)' vulnerability in User Post Gallery plugin for WordPress affects v. through 2.19.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.4k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-4060
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

The User Post Gallery WordPress plugin through 2.19 does not limit what callback functions can be called by users, making it possible to any visitors to run code on sites running it.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
User Post Gallery
0
Updated Aug 22, 2026View on NVD →
Detail

The User Post Gallery plugin is a WordPress plugin utilized to showcase user-generated content on websites. It allows users to submit images and videos through a submission form, which can then be displayed in a gallery on the website. This plugin is often used by websites that wish to display the work of their community or offer a platform for sharing visual content.

Recently, a security vulnerability has been detected in this plugin, known as CVE-2022-4060. This vulnerability allows visitors to the website to call and execute any callback function, which can potentially lead to malicious code being run on the website. This issue is present in versions up to 2.19 of the User Post Gallery plugin.

If exploited, the vulnerability can have serious implications for the website and its users. Attackers can use this vulnerability to execute remote code on the server, gaining access to confidential data, injecting malware, and taking control of the website. This can lead to a loss of reputation, legal action, and financial damage.

By utilizing the pro features of the s4e.io platform, readers of this article can quickly and easily learn about vulnerabilities present in their digital assets. This platform provides regular updates on various security issues, including detailed reports on how to address and fix them. Additionally, the platform offers various tools and resources that can help website owners protect their sites from threats and maintain their digital security.

 

REFERENCES

Solution Advice

To protect against this vulnerability, the following precautions can be taken:

  • Update User Post Gallery plugin to the latest version (2.20 or higher).
  • Remove any unused callback functions from the website’s code.
  • Implement a web application firewall (WAF) to protect against malicious code injection.
  • Restrict access to sensitive parts of the website using proper authentication measures.
  • Regularly monitor the website for any signs of malicious activity.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.