CVE-2022-4328 is a critical arbitrary file upload vulnerability affecting the WooCommerce Checkout Field Manager WordPress plugin prior to version 18.0. This flaw allows unauthenticated attackers to upload malicious files, such as PHP scripts, to the server. With a CVSS score of 9.8 (CRITICAL) and an EPSS score indicating high exploitability, this vulnerability poses a significant risk due to its low attack complexity and potential for complete compromise of confidentiality, integrity, and availability. While not yet listed in CISA's KEV catalog, exploit intelligence shows available Nuclei templates and significant community discussion, suggesting a high likelihood of future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 18.0CPE matchmatch criteria | cpe:2.3:a:najeebmedia:woocommerce_checkout_field_manager:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.