WooCommerce Checkout Field Manager < 18.0 - Unauthenticated Arbitrary File Upload
85Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actcvss 9.8epss 4.4%
from disclosure to weapon
Published on NVDMar 6
VulnCheck+322d
exploitation probability
4.4%top 10% of all CVEs
observed exploitation
yesVulnCheck
1 public exploit(s)
The WooCommerce Checkout Field Manager WordPress plugin before 18.0 does not validate files to be uploaded, which could allow unauthenticated attackers to upload arbitrary files such as PHP on the server
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Unknown · WooCommerce Checkout Field Managerpublic PoCs found — 1
cve_referencewpscan.com/vulnerability/4dc72cd2-81d7-4a66-86bd-c9cfaf690eedunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.