Membership For WooCommerce < 2.1.7 - Unauthenticated Arbitrary File Upload
53Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 9.8epss 18%
from disclosure to weapon38 days
Published on NVDJan 30
1st PoC+38d
exploitation probability
18%top 3% of all CVEs
observed exploitation
nono source reports it
4 public exploit(s)
The Membership For WooCommerce WordPress plugin before 2.1.7 does not validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as malicious PHP code, and achieve RCE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Unknown · Membership For WooCommercepublic PoCs found — 4
cve_referencewww.exploit-db.com/exploits/51959unverifiedgithubgithub.com/MrG3P5/CVE-2022-4395★ 7cve_referencepacketstormsecurity.com/files/177934/WordPress-Membership-For-WooCommerce-Shell-Upload.htmlunverifiedcve_referencewpscan.com/vulnerability/80407ac4-8ce3-4df7-9c41-007b69045c40unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.