First published: Mon Jan 30 2023(Updated: )
The Membership For WooCommerce WordPress plugin before 2.1.7 does not validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as malicious PHP code, and achieve RCE.
Credit: contact@wpscan.com Milad karimi contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Wpswings Membership For Woocommerce | <2.1.7 | |
<2.1.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-4395.
The severity of CVE-2022-4395 is classified as critical with a severity value of 9.8.
The affected software for CVE-2022-4395 is the Membership For WooCommerce WordPress plugin version up to 2.1.7.
CVE-2022-4395 could allow unauthenticated users to upload arbitrary files, such as malicious PHP code, and achieve remote code execution.
To fix CVE-2022-4395, it is recommended to update the Membership For WooCommerce WordPress plugin to version 2.1.7 or later.