CVE-2022-4047
Published on: Not Yet Published
Last Modified on: 01/10/2023 10:09:18 AM UTC
Certain versions of Return Refund And Exchange For Woocommerce from Wpswings contain the following vulnerability:
The Return Refund and Exchange For WooCommerce WordPress plugin before 4.0.9 does not validate attachment files to be uploaded via an AJAX action available to unauthenticated users, which could allow them to upload arbitrary files such as PHP and lead to RCE
- CVE-2022-4047 has been assigned by
[email protected] to track the vulnerability - currently rated as CRITICAL severity.
- Affected Vendor/Software:
Unknown - Return Refund and Exchange For WooCommerce version = 0
CVSS3 Score: 9.8 - CRITICAL
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Return Refund and Exchange For WooCommerce < 4.0.9 - Unauthenticated Arbitrary File Upload WordPress Security Vulnerability | web.archive.org text/html Inactive LinkNot Archived |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Wpswings | Return Refund And Exchange For Woocommerce | All | All | All | All |
- cpe:2.3:a:wpswings:return_refund_and_exchange_for_woocommerce:*:*:*:*:*:wordpress:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-4047 : The Return Refund and Exchange For WooCommerce WordPress plugin before 4.0.9 does not validate atta… twitter.com/i/web/status/1… | 2022-12-26 13:08:33 |