CVE-2022-4328: WooCommerce Checkout Field Manager < 18.0 - Unauthenticated Arbitrary File Upload
The WooCommerce Checkout Field Manager WordPress plugin before 18.0 does not validate files to be uploaded, which could allow unauthenticated attackers to upload arbitrary files such as PHP on the server
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-4328?
CVE-2022-4328 is a vulnerability in the WooCommerce Checkout Field Manager WordPress plugin before version 18.0 that allows unauthenticated attackers to upload arbitrary files such as PHP on the server.
What is the severity of CVE-2022-4328?
CVE-2022-4328 is classified as critical with a severity score of 9.8 out of 10.
How does CVE-2022-4328 affect the WooCommerce Checkout Field Manager WordPress plugin?
CVE-2022-4328 affects the WooCommerce Checkout Field Manager WordPress plugin before version 18.0 by not validating files to be uploaded, which allows unauthenticated attackers to upload arbitrary files on the server.
How can unauthenticated attackers exploit CVE-2022-4328?
Unauthenticated attackers can exploit CVE-2022-4328 by uploading arbitrary files, such as PHP, on the server.
How can I fix CVE-2022-4328 in the WooCommerce Checkout Field Manager WordPress plugin?
To fix CVE-2022-4328, update the WooCommerce Checkout Field Manager WordPress plugin to version 18.0 or later, which includes the fix for validating files to be uploaded.