CVE-2022-4395

CVE-2022-4395: Membership For WooCommerce < 2.1.7 - Unauthenticated Arbitrary File Upload

Vendor Unknown
Product Membership For WooCommerce
Published January 30, 2023
Last update March 27, 2025

CVSS base score

What the vulnerability does

01Description

The Membership For WooCommerce WordPress plugin before 2.1.7 does not validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as malicious PHP code, and achieve RCE.

Key dates

02Disclosure timeline

January 30, 2023 CVE published
March 27, 2025 Record updated