Security Advisory

CVE-2022-3900

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2022-12-12 17:57:08
Last updated 2025-04-22 14:43:41
Assigner WPScan
State PUBLISHED

Description

The Cooked Pro WordPress plugin before 1.7.5.7 does not properly validate or sanitize the recipe_args parameter before unserializing it in the cooked_loadmore action, allowing an unauthenticated attacker to trigger a PHP Object injection vulnerability.