Critical severity9.8NVD Advisory· Published Jun 20, 2026· Updated Jun 22, 2026
CVE-2022-50972
CVE-2022-50972
Description
WooCommerce 7.1.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary PHP code by injecting shell commands through the product-type parameter. Attackers can send requests to the class-wc-meta-box-product-images.php endpoint with unsanitized product-type values to write malicious PHP files to the web root.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
3News mentions
1- 25 WordPress Plugin CVEs Drop in Three Days: File Deletion, SSRF, and XSS Dominate the BatchVypr Intelligence · Jun 22, 2026