Unrated severityNVD Advisory· Published Jun 20, 2026
WooCommerce 7.1.0 Remote Code Execution via class-wc-meta-box-product-images.php
CVE-2022-50972
Description
WooCommerce 7.1.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary PHP code by injecting shell commands through the product-type parameter. Attackers can send requests to the class-wc-meta-box-product-images.php endpoint with unsanitized product-type values to write malicious PHP files to the web root.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
3- www.exploit-db.com/exploits/51156mitreexploit
- www.vulncheck.com/advisories/woocommerce-remote-code-execution-via-class-wc-meta-box-product-images-phpmitrethird-party-advisory
- wordpress.org/plugins/woocommercemitreproduct
News mentions
1- 25 WordPress Plugin CVEs Drop in Three Days: File Deletion, SSRF, and XSS Dominate the BatchVypr Intelligence · Jun 22, 2026