← back
CVE-2022-4328criticalobserved exploitation

WooCommerce Checkout Field Manager < 18.0 - Unauthenticated Arbitrary File Upload

85Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actcvss 9.8epss 4.4%
from disclosure to weapon
Published on NVDMar 6
VulnCheck+322d
exploitation probability
4.4%top 10% of all CVEs
observed exploitation
yesVulnCheck
1 public exploit(s)
The WooCommerce Checkout Field Manager WordPress plugin before 18.0 does not validate files to be uploaded, which could allow unauthenticated attackers to upload arbitrary files such as PHP on the server
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.