Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 22 Jun 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 20 Jun 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Woocommerce
Woocommerce woocommerce Wordpress Wordpress wordpress |
|
| Vendors & Products |
Woocommerce
Woocommerce woocommerce Wordpress Wordpress wordpress |
Sat, 20 Jun 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | WooCommerce 7.1.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary PHP code by injecting shell commands through the product-type parameter. Attackers can send requests to the class-wc-meta-box-product-images.php endpoint with unsanitized product-type values to write malicious PHP files to the web root. | |
| Title | WooCommerce 7.1.0 Remote Code Execution via class-wc-meta-box-product-images.php | |
| Weaknesses | CWE-94 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-22T12:45:33.935Z
Reserved: 2026-01-11T13:34:26.334Z
Link: CVE-2022-50972
Updated: 2026-06-22T12:45:29.661Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-20T16:30:08Z