AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2022-2441

HIGH · CVSS 8.8 EPSS 1.07% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2023-10-20 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 8.8. It affects WordPress. Public exploit code or proof-of-concept references have been detected in its references. It may be remotely exploitable. Exploitation may require the attacker to be authenticated.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution
External Security References

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2022-2441
Severity
HIGH
CVSS
8.8
EPSS
1.07%
WordPress

Original NVD Description

The ImageMagick Engine plugin for WordPress is vulnerable to remote code execution via the 'cli_path' parameter in versions up to, and including 1.7.5. This makes it possible for unauthenticated users to run arbitrary commands leading to remote command execution, granted they can trick a site administrator into performing an action such as clicking on a link. This makes it possible for an attacker to create and or modify files hosted on the server which can easily grant attackers backdoor access to the affected server.

Related CVEs

Other vulnerabilities affecting the same vendor(s)