CVE-2022-50972: WooCommerce 7.1.0 Remote Code Execution via class-wc-meta-box-product-images.php
Published Jun 20, 2026
·Updated
WooCommerce 7.1.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary PHP code by injecting shell commands through the product-type parameter. Attackers can send requests to the class-wc-meta-box-product-images.php endpoint with unsanitized product-type values to write malicious PHP files to the web root.
Affected Software
1 affected component
Automattic WooCommerce=7.1.0
Event History
Jun 20, 2026
CVE Published
via MITRE·01:37 PM
Data Sourced
via MITRE·01:37 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-50972?
CVE-2022-50972 has a critical severity rating of 9.8.
2
How do I fix CVE-2022-50972?
To fix CVE-2022-50972, update to the latest version of WooCommerce that addresses this vulnerability.
3
What type of vulnerability is CVE-2022-50972?
CVE-2022-50972 is a remote code execution vulnerability caused by code injection.
4
What can attackers achieve by exploiting CVE-2022-50972?
Attackers can execute arbitrary PHP code on the affected WooCommerce instance by exploiting CVE-2022-50972.
5
Which version of WooCommerce is affected by CVE-2022-50972?
WooCommerce version 7.1.0 is affected by CVE-2022-50972.