CVE-2022-4047
Last modified
CVE-2022-4047 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. The Return Refund and Exchange For WooCommerce WordPress plugin before 4.0.9 does not validate attachment files to be uploaded via an AJAX action available to unauthenticated users, which could allow them to upload arbitrary files such as PHP and lead to RCE. EPSS estimates a 6.15% chance of exploitation in the next 30 days.
Description
The Return Refund and Exchange For WooCommerce WordPress plugin before 4.0.9 does not validate attachment files to be uploaded via an AJAX action available to unauthenticated users, which could allow them to upload arbitrary files such as PHP and lead to RCE
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Wpswings | Return Refund And Exchange For Woocommerce | < 4.0.9 |
References
- https://wpscan.com/vulnerability/8965a87c-5fe5-4b39-88f3-e00966ca1d94Exploit, Third Party Advisory
- https://wpscan.com/vulnerability/8965a87c-5fe5-4b39-88f3-e00966ca1d94Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-4047?
How severe is CVE-2022-4047?
How do I fix CVE-2022-4047?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-40446ZZCMS 2022 was discovered to contain a SQL injection vulnera…7.2
- CVE-2022-40447ZZCMS 2022 was discovered to contain a SQL injection vulnera…7.2
- CVE-2022-4045A denial-of-service vulnerability in the Mattermost allows a…6.5
- CVE-2022-4046In CODESYS Control in multiple versions a improper restricti…8.8
- CVE-2022-40468Potential leak of left-over heap data if custom error page t…7.5
- CVE-2022-40469iKuai OS v3.6.7 was discovered to contain an authenticated r…8.8
- CVE-2022-40470Phpgurukul Blood Donor Management System 1.0 allows Cross Si…4.8
- CVE-2022-40471Remote Code Execution in Clinic's Patient Management System …9.8
- CVE-2022-40472ZKTeco Xiamen Information Technology ZKBio Time 8.0.7 Build:…8
- CVE-2022-40475TOTOLINK A860R V4.1.2cu.5182_B20201027 was discovered to con…9.8
- CVE-2022-40476A null pointer dereference issue was discovered in fs/io_uri…5.5
- CVE-2022-4048Inadequate Encryption Strength in CODESYS Development System…7.7
Are you affected by CVE-2022-4047?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
