CVE-2022-4047
9.8
CRITICAL · CVSS 3.1 · EPSS 6.2% (pctl 93)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
The Return Refund and Exchange For WooCommerce WordPress plugin before 4.0.9 does not validate attachment files to be uploaded via an AJAX action available to unauthenticated users, which could allow them to upload arbitrary files such as PHP and lead to RCE
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 6.22% — more likely to be exploited than 93% of all CVEs |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2022-12-26 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| wpswings | return refund and exchange for woocommerce |
References
→ the Explorer · watch your stack · NVD