PT-2026-51141 · WordPress · Woocommerce

·

CVE-2022-50972

·

Published

2026-06-20

·

Updated

2026-06-22

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WooCommerce version 7.1.0
Description A remote code execution flaw exists in the 'class-wc-meta-box-product-images.php' endpoint. The product-type parameter is processed without proper sanitization, allowing attackers to inject shell commands. This can lead to the creation of malicious PHP files within the web root, enabling the execution of arbitrary PHP code on the server.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-50972

Affected Products

Woocommerce