PoC Index

CVE-2022-4395

CRITICAL 9.8EPSS 17.6%

The Membership For WooCommerce WordPress plugin before 2.1.7 does not validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as malicious PHP code, and achieve RCE.

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
17.57% chance of exploitation in the next 30 days, 97th percentile
Published
2023-01-30
Updated
2025-03-27

Proof-of-concept exploits (2)

ExploitDB entries (1)

References

Related