1 results (0.001 seconds)
CVSS: 10.0EPSS: 5%CPEs: 1EXPL: 3
CVE-2022-4395 – Membership For WooCommerce < 2.1.7 - Unauthenticated Arbitrary File Upload
https://notcve.org/view.php?id=CVE-2022-4395
04 Jan 2023 — The Membership For WooCommerce WordPress plugin before 2.1.7 does not validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as malicious PHP code, and achieve RCE. The Membership For WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in versions up to, and including, 2.1.6. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code e... • https://www.exploit-db.com/exploits/51959 • CWE-434: Unrestricted Upload of File with Dangerous Type •