WP Clinic
Log in Sign up

CVE · Critical

CVE-2022-50972 — WooCommerce [woocommerce] == 7.1.0 (unfixed)

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-50972 WooCommerce [woocommerce] == 7.1.0 (unfixed) Critical 9.8 < 7.1.0 7.1.0 2026-06-20

CVE-2022-50972

WooCommerce 7.1.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary PHP code by injecting shell commands through the product-type parameter. Attackers can send requests to the class-wc-meta-box-product-images.php endpoint with unsanitized product-type values to write malicious PHP files to the web root.

Source: CVE.org

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.