Vulnerability CVE-2022-4395


Published: 2023-01-30

Description:
The Membership For WooCommerce WordPress plugin before 2.1.7 does not validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as malicious PHP code, and achieve RCE.

Type:

CWE-434

(Unrestricted Upload of File with Dangerous Type)

 References:
https://wpscan.com/vulnerability/80407ac4-8ce3-4df7-9c41-007b69045c40

Copyright 2026, cxsecurity.com

 

Back to Top