Return Refund and Exchange For WooCommerce < 4.0.9 - Unauthenticated Arbitrary File Upload
48Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 9.8epss 6.2%
from disclosure to weapon274 days
Published on NVDDec 26
1st PoC+274d
exploitation probability
6.2%top 7% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
The Return Refund and Exchange For WooCommerce WordPress plugin before 4.0.9 does not validate attachment files to be uploaded via an AJAX action available to unauthenticated users, which could allow them to upload arbitrary files such as PHP and lead to RCE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Unknown · Return Refund and Exchange For WooCommercepublic PoCs found — 3
githubgithub.com/im-hanzou/WooRefer★ 1githubgithub.com/entroychang/CVE-2022-4047★ 0cve_referencewpscan.com/vulnerability/8965a87c-5fe5-4b39-88f3-e00966ca1d94unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.