CVE-2022-4328
PoC —CVSS 3.1
9.8 critical
EPSS
4%p91
Published
()
Modified
Description
The WooCommerce Checkout Field Manager WordPress plugin before 18.0 does not validate files to be uploaded, which could allow unauthenticated attackers to upload arbitrary files such as PHP on the server
- Vendors
- najeebmedia
- Products
- woocommerce checkout field manager
- Ecosystems
- WordPress, E-commerce
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.