CVE-2022-4395: Membership For WooCommerce < 2.1.7 - Unauthenticated Arbitrary File Upload
Published Jan 30, 2023
·Updated
The Membership For WooCommerce WordPress plugin before 2.1.7 does not validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as malicious PHP code, and achieve RCE.
Credit
Milad karimi
Affected Software
1 affected component
Wpswings Membership For Woocommerce Wordpress<2.1.7
Event History
Jan 30, 2023
CVE Published
via MITRE·08:31 PM
Data Sourced
via MITRE·08:31 PM
DescriptionWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityAffected Software
Apr 2, 2024
Exploit Published
via ExploitDB·12:00 AM
Known Exploited
via ExploitDB·12:00 AM
Frequently Asked Questions
1
What is the vulnerability ID for the Membership For WooCommerce WordPress plugin?
The vulnerability ID is CVE-2022-4395.
2
What is the severity of CVE-2022-4395?
The severity of CVE-2022-4395 is classified as critical with a severity value of 9.8.
3
What is the affected software for CVE-2022-4395?
The affected software for CVE-2022-4395 is the Membership For WooCommerce WordPress plugin version up to 2.1.7.
4
What is the potential impact of CVE-2022-4395?
CVE-2022-4395 could allow unauthenticated users to upload arbitrary files, such as malicious PHP code, and achieve remote code execution.
5
How can I fix CVE-2022-4395?
To fix CVE-2022-4395, it is recommended to update the Membership For WooCommerce WordPress plugin to version 2.1.7 or later.