Sploitus

CVE-2022-4395

3 known exploits for CVE-2022-4395

The Membership For WooCommerce WordPress plugin before 2.1.7 does not validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as malicious PHP code, and achieve RCE.

Wpswings Membership For Woocommerce
< 2.1.7
Fix
Available
CVSS 3.1
9.8 CRITICAL
EPSS
17.6% (97th percentile)
NVD status
Modified
Published
2023-01-30
CVE-2022-4395 at NVD
Authoritative description, scoring and affected products

3 known exploits for CVE-2022-4395

Proof-of-concept code and exploit modules indexed by Sploitus