CVE · Critical

CVE-2022-50972 — WooCommerce [woocommerce] == 7.1.0 (unfixed)

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-50972 WooCommerce [woocommerce] == 7.1.0 (unfixed) Critical 9.8 < 7.1.0 7.1.0 2026-06-20

CVE-2022-50972

WooCommerce version 7.1.0 is vulnerable to remote code execution through improper handling of the product-type parameter in the class-wc-meta-box-product-images.php endpoint. An attacker can exploit this flaw by sending specially crafted requests containing unsanitized shell commands in the product-type field, allowing them to write and execute malicious PHP files in the web root directory. This vulnerability remains unpatched in the affected version.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.