CVE-2022-4395
CRITICAL 9.8EPSS 17.6%
The Membership For WooCommerce WordPress plugin before 2.1.7 does not validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as malicious PHP code, and achieve RCE.
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS
- 17.57% chance of exploitation in the next 30 days, 97th percentile
- Published
- 2023-01-30
- Updated
- 2025-03-27
Proof-of-concept exploits (2)
- https://wpscan.com/vulnerability/80407ac4-8ce3-4df7-9c41-007b69045c40
- MrG3P5/CVE-2022-43957★ · 2023-03-09