CVE-2022-4047
Return Refund and Exchange For WooCommerce < 4.0.9 - Unauthenticated Arbitrary File Upload
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
The Return Refund and Exchange For WooCommerce WordPress plugin before 4.0.9 does not validate attachment files to be uploaded via an AJAX action available to unauthenticated users, which could allow them to upload arbitrary files such as PHP and lead to RCE
El complemento Return Refund and Exchange For WooCommerce de WordPress anterior a 4.0.9 no valida que los archivos adjuntos se carguen mediante una acción AJAX disponible para usuarios no autenticados, lo que podría permitirles cargar archivos arbitrarios como PHP y conducir a RCE.
The Return Refund and Exchange For WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the wps_rma_order_return_attach_files function in versions up to, and including, 4.0.8. This makes it possible for authenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-11-17 CVE Reserved
- 2022-11-25 CVE Published
- 2023-09-26 First Exploit
- 2024-08-03 CVE Updated
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-434: Unrestricted Upload of File with Dangerous Type
CAPEC
References (3)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://github.com/entroychang/CVE-2022-4047 | 2023-12-15 | |
https://github.com/im-hanzou/WooRefer | 2023-09-26 | |
https://wpscan.com/vulnerability/8965a87c-5fe5-4b39-88f3-e00966ca1d94 | 2024-08-03 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Wpswings Search vendor "Wpswings" | Return Refund And Exchange For Woocommerce Search vendor "Wpswings" for product "Return Refund And Exchange For Woocommerce" | < 4.0.9 Search vendor "Wpswings" for product "Return Refund And Exchange For Woocommerce" and version " < 4.0.9" | wordpress |
Affected
|