CVE-2022-4395 EXPLOIT
9.8
CRITICAL · CVSS 3.1 · EPSS 17.6% (pctl 97)
Patch early
A public exploit exists.
Description
The Membership For WooCommerce WordPress plugin before 2.1.7 does not validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as malicious PHP code, and achieve RCE.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 17.57% — more likely to be exploited than 97% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2023-01-30 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| wpswings | membership for woocommerce |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Wordpress Plugin - Membership For WooCommerce < v2.1.7 - Arbitrary File Upload to Shell (Unauthenticated) | 2024-04-02 |
References
→ the Explorer · watch your stack · NVD