PoC Index

CVE-2022-4328

CRITICAL 9.8EPSS 4.4%

The WooCommerce Checkout Field Manager WordPress plugin before 18.0 does not validate files to be uploaded, which could allow unauthenticated attackers to upload arbitrary files such as PHP on the server

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
4.43% chance of exploitation in the next 30 days, 91th percentile
Nuclei
critical · CWE-434
Published
2023-03-06
Updated
2025-03-04

Proof-of-concept exploits (1)

Nuclei templates (1)

References

Related