← All CVEs

CVE-2022-4395

critical · 9.8

The Membership For WooCommerce WordPress plugin before 2.1.7 does not validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as malicious PHP code, and achieve RCE.

9.8
CVSS
17.6%
EPSS (exploit prob.)
97th
EPSS percentile
2023-01-30
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

VendorProductAffected versions
wpswingsmembership_for_woocommerce< 2.1.7

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2022-4395