Remote Code Execution Vulnerability in WooCommerce by Automattic
CVE-2022-50972
Key Information:
- Vendor
WooCommerce
- Status
- Vendor
- CVE Published:
- 20 June 2026
Badges
What is CVE-2022-50972?
WooCommerce version 7.1.0 has a vulnerability that allows remote code execution. This flaw enables attackers to execute arbitrary PHP code by injecting untrusted shell commands through the product-type parameter. By sending crafted requests to the class-wc-meta-box-product-images.php endpoint, attackers can exploit unsanitized product-type values to create malicious PHP files on the web server's root directory. This exploit poses significant risks to web applications using the affected version of WooCommerce, highlighting the need for immediate security updates and best practices in input validation.
Affected Version(s)
WooCommerce 7.1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
