CVE-2022-50972
WooCommerce version 7.1.0 is vulnerable to remote code execution through improper handling of the product-type parameter in the class-wc-meta-box-product-images.php endpoint. An attacker can exploit this flaw by sending specially crafted requests containing unsanitized shell commands in the product-type field, allowing them to write and execute malicious PHP files in the web root directory. This vulnerability remains unpatched in the affected version.
Based on public CVE data (MITRE/NVD).