peter bassill · operator
$ cve CVE-2022-4395 JSON

CVE-2022-4395 EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 17.6% (pctl 97)

Patch early

A public exploit exists.

Description

The Membership For WooCommerce WordPress plugin before 2.1.7 does not validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as malicious PHP code, and achieve RCE.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS17.57% — more likely to be exploited than 97% of all CVEs
On CISA KEVno
Public exploityes
Published2023-01-30
Last modified2026-06-17

Affected (1)

VendorProduct
wpswingsmembership for woocommerce

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD