CVE-2022-50972 WooCommerce 7.1.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary PHP code by injecting shell commands through the product-t… https://www.cve.org/CVERecord?id=CVE-2022-50972
Post summary
The text announces a remote code execution vulnerability (CVE-2022-50972) in WooCommerce 7.1.0 that permits arbitrary PHP code injection through shell commands.
🚨Critical - WooCommerce Remote Code Execution via product-type Parameter (CVE-2022-50972)
WooCommerce 7.1.0 contains a remote code execution flaw in the class-wc-meta-box-product-images.php endpoint. The product-type parameter is passed unsanitized, allowing an attacker to inject shell commands and write malicious PHP files into the web root, resulting in arbitrary PHP code execution.
The bug is remotely exploitable with no privileges and no user interaction, and a public proof-of-concept exploit is available on Exploit-DB, putting affected WordPress stores at direct risk of full server compromise.
👉Affected: WooCommerce 7.1.0.
Post summary
WooCommerce 7.1.0 has a remote code execution flaw via an unsanitized product‑type parameter; a public PoC exploit on Exploit‑DB demonstrates the exploitability and risks full server compromise.