CVE-2022-4328

CVE-2022-4328: WooCommerce Checkout Field Manager < 18.0 - Unauthenticated Arbitrary File Upload

Vendor Unknown
Product WooCommerce Checkout Field Manager
Published March 6, 2023
Last update March 4, 2025

CVSS base score

What the vulnerability does

01Description

The WooCommerce Checkout Field Manager WordPress plugin before 18.0 does not validate files to be uploaded, which could allow unauthenticated attackers to upload arbitrary files such as PHP on the server

Key dates

02Disclosure timeline

March 6, 2023 CVE published
March 4, 2025 Record updated