CRITICAL

CVE-2022-4395

CVSS v3

9.8

CRITICAL

EPSS Score

77.4%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

The Membership For WooCommerce WordPress plugin before 2.1.7 does not validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as malicious PHP code, and achieve RCE.

Technical details

Published
1/30/2023

Frequently asked questions

What is CVE-2022-4395?

The Membership For WooCommerce WordPress plugin before 2.1.7 does not validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as malicious PHP code, and achieve RCE.

Is CVE-2022-4395 actively exploited?

Active exploitation of CVE-2022-4395 has not been confirmed. The EPSS score is 77.4%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2022-4395?

CVE-2022-4395 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2022-4395 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.