← Back to browse · API

CVE-2022-4047

Severity
CRITICAL
CVSS
9.8
EPSS
0.06152
Risk score
41.35
CISA KEV
No
PoC
No
Published
2022-12-26
Modified
2025-04-14
First seen
2026-08-07
Aliases
EUVD-2022-51424, GHSA-3J85-6864-55P3
Products
wpswings:Return Refund and Exchange For WooCommerce 0 <4.0.9
Sources
euvd EUVD-2022-51424

Description

The Return Refund and Exchange For WooCommerce WordPress plugin before 4.0.9 does not validate attachment files to be uploaded via an AJAX action available to unauthenticated users, which could allow them to upload arbitrary files such as PHP and lead to RCE

References