ZeroHour

CVE-2022-4328

PoC
CVSS 3.1
9.8 critical
EPSS
4%p91
Published
()
Modified
Description

The WooCommerce Checkout Field Manager WordPress plugin before 18.0 does not validate files to be uploaded, which could allow unauthenticated attackers to upload arbitrary files such as PHP on the server

Vendors
najeebmedia
Products
woocommerce checkout field manager
Ecosystems
WordPress, E-commerce
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.