9.8
CVE-2022-4328
- EPSS 4.43%
- Veröffentlicht 06.03.2023 14:15:09
- Zuletzt bearbeitet 04.03.2025 20:15:35
- Erkennungen
WooCommerce Checkout Field Manager < 18.0 - Unauthenticated Arbitrary File Upload
WooCommerce Checkout Field Manager <= 17.3 - Unauthenticated Arbitrary File Upload
The WooCommerce Checkout Field Manager WordPress plugin before 18.0 does not validate files to be uploaded, which could allow unauthenticated attackers to upload arbitrary files such as PHP on the server
Mögliche Gegenmaßnahme
WooCommerce Checkout Field Manager: Update to version 18.0, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Najeebmedia ≫ Woocommerce Checkout Field Manager SwPlatform wordpress Version < 18.0
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
WooCommerce Checkout Field Manager
Version
*-17.3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 4.43% | 0.901 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| CISA-ADP | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
https://wpscan.com/vulnerability/4dc72cd2-81d7-4a66-86bd-c9cfaf690eed
https://www.wordfence.com/threat-intel/vulnerabilities/id/9be94d63-f027-4988-ab41-673658c1fa5f