Beveiligingsadvies

CVE-2022-3900

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2022-12-12 17:57:08
Laatst bijgewerkt 2025-04-22 14:43:41
Toegewezen door WPScan
CVSS-score 9.8
Status PUBLISHED

Beschrijving

The Cooked Pro WordPress plugin before 1.7.5.7 does not properly validate or sanitize the recipe_args parameter before unserializing it in the cooked_loadmore action, allowing an unauthenticated attacker to trigger a PHP Object injection vulnerability.