Record summary

CVE-2022-4328 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

The WooCommerce Checkout Field Manager WordPress plugin before 18.0 does not validate files to be uploaded, which could allow unauthenticated attackers to upload arbitrary files such as PHP on the server

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jan 22, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 4, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

WooCommerce Checkout Field Manager

Default status: unaffected

CVE ListBefore 18.0affected
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryCRITICALWooCommerce Checkout Field Manager < 18.0 - Arbitrary File UploadCVSS 9.8

The WooCommerce Checkout Field Manager WordPress plugin before 18.0 does not validate files to be uploaded, which could allow unauthenticated attackers to upload arbitrary files such as PHP on the server.

Impact

Unauthenticated attackers can upload arbitrary PHP files through the cfom_upload_file AJAX action without validation, achieving remote code execution on the WordPress server and potentially compromising the entire WooCommerce installation.

Remediation

Fixed in version 18.0

WeaknessesCWE-434
Authorstheamanrawat
Template tagscve2022cvewpn-media-woocommerce-checkout-fieldswpscanrcewordpresswp-pluginintrusivenajeebmediafileuploadvkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:najeebmedia:woocommerce_checkout_field_manager:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

2