Zero-Day vulnerability in WPGateway Plugin compromises WordPress sites

Red | Vulnerability Report

The recently uncovered CVE-2022-3180 zero-day vulnerability allows an unauthenticated attacker to add an administrator account to WPGateway-powered websites. WPGateway is a commercial plugin that allows users to install, backup, and clone WordPress. The flaw is being actively abused, and no patch has been issued yet.

Reduce real exposure. Not just vulnerability volume.