CVE-2022-4395

The Membership For WooCommerce WordPress plugin before 2.1.7 does not validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as malicious PHP code, and achieve RCE.
References
Configurations

Configuration 1

cpe:2.3:a:wpswings:membership_for_woocommerce:*:*:*:*:*:wordpress:*:*

Information

Published : 2023-01-30 09:15

Updated : 2023-02-06 07:55


NVD link : CVE-2022-4395

Mitre link : CVE-2022-4395

Products Affected
No products.
CWE