ZeroHour

CVE-2022-4395

PoC
CVSS 3.1
9.8 critical
EPSS
18%p97
Published
()
Modified
Description

The Membership For WooCommerce WordPress plugin before 2.1.7 does not validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as malicious PHP code, and achieve RCE.

Vendors
wpswings
Products
membership for woocommerce
Ecosystems
WordPress, E-commerce
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.