CVE-2022-45359 is a critical arbitrary file upload vulnerability affecting the YITH WooCommerce Gift Cards premium plugin for WordPress, specifically versions 3.19.0 and earlier. With a CVSS score of 9.8, this unauthenticated flaw allows remote attackers to upload malicious files, leading to complete compromise of the affected system (confidentiality, integrity, and availability). This vulnerability is actively being exploited in the wild, as evidenced by media coverage from BleepingComputer and SecurityWeek, and has garnered significant community discussion, despite no public exploit code being available in Metasploit, Nuclei, or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.19.0CPE matchmatch criteria | cpe:2.3:a:yithemes:yith_woocommerce_gift_cards:*:*:*:*:premium:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.