CVE Published: 30/01/2023 |
CVE Updated: 02/12/2024 |
CVE Year: 2022 Source: WPScan |
Vendor: Unknown |
Product: Membership For WooCommerce Status : PUBLISHED
CVE-2022-4395 Description
The Membership For WooCommerce WordPress plugin before 2.1.7 does not validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as malicious PHP code, and achieve RCE.