Aller au contenu

Fiche vulnérabilité

CVE-2022-4047 : faille critique wpswings return refund and exchange… (CVSS 9.8)

Description

The Return Refund and Exchange For WooCommerce WordPress plugin before 4.0.9 does not validate attachment files to be uploaded via an AJAX action available to unauthenticated users, which could allow them to upload arbitrary files such as PHP and lead to RCE

En bref

Sévérité
Critique (CVSS 9.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
26 déc. 2022
Dernière mise à jour
17 juin 2026

Produits concernés

  • wpswings return refund and exchange for woocommerce

Références

Rechercher une autre vulnérabilité dans la base CVE