CVE-2022-50972Disclosure

LOW

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

3.5/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-06-21)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-06-20: 1Mentions · 2026-06-21: 2PoC Mentioned / Linked · 2026-06-20: 1Exploit Tool / Code · 2026-06-20: 1Technical Details · 2026-06-20: 1Technical Details · 2026-06-21: 206-2006-21
Signal classification2 categories
Disclosure
266.7%
Exploit
133.3%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-06-201
Exploit1
2026-06-212
Disclosure2
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2022-50972 WooCommerce 7.1.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary PHP code by injecting shell commands through the product-t… https://www.cve.org/CVERecord?id=CVE-2022-50972

    Post summary

    The text announces a remote code execution vulnerability (CVE-2022-50972) in WooCommerce 7.1.0 that permits arbitrary PHP code injection through shell commands.

    00010451
    57.7K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2022-50972 WooCommerce 7.1.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary PHP code by injecting shell commands through the product-t… https://www.cve.org/CVERecord?id=CVE-2022-50972 ----- Traducción: CVE-2022-50972 Woo… http://infoflow.cloud`

    Post summary

    The post announces a remote code execution flaw in WooCommerce 7.1.0 (CVE‑2022‑50972), describing the RCE vector and linking to the CVE record.

    0000041
    88 followersView on X
  • Upwind Security MDR@UpwindMDR
    Exploit

    🚨Critical - WooCommerce Remote Code Execution via product-type Parameter (CVE-2022-50972) WooCommerce 7.1.0 contains a remote code execution flaw in the class-wc-meta-box-product-images.php endpoint. The product-type parameter is passed unsanitized, allowing an attacker to inject shell commands and write malicious PHP files into the web root, resulting in arbitrary PHP code execution. The bug is remotely exploitable with no privileges and no user interaction, and a public proof-of-concept exploit is available on Exploit-DB, putting affected WordPress stores at direct risk of full server compromise. 👉Affected: WooCommerce 7.1.0.

    Post summary

    WooCommerce 7.1.0 has a remote code execution flaw via an unsanitized product‑type parameter; a public PoC exploit on Exploit‑DB demonstrates the exploitability and risks full server compromise.

    00000111
    223 followersView on X

Explore more