← back
CVE-2022-4395critical

Membership For WooCommerce < 2.1.7 - Unauthenticated Arbitrary File Upload

53Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 9.8epss 18%
from disclosure to weapon38 days
Published on NVDJan 30
1st PoC+38d
exploitation probability
18%top 3% of all CVEs
observed exploitation
nono source reports it
4 public exploit(s)
The Membership For WooCommerce WordPress plugin before 2.1.7 does not validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as malicious PHP code, and achieve RCE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.