PT-2022-24656 · WordPress · Cooked Pro Wordpress Plugin

Marcin Motwicki

+1

·

Published

2022-12-12

·

Updated

2025-04-22

·

CVE-2022-3900

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cooked Pro WordPress plugin versions prior to 1.7.5.7
Description The issue arises from improper validation and sanitization of the recipe args parameter before unserializing it in the "cooked loadmore" action. This allows an unauthenticated attacker to trigger a PHP Object injection issue.
Recommendations For versions prior to 1.7.5.7, update to version 1.7.5.7 or later to resolve the issue. As a temporary workaround, consider restricting access to the "cooked loadmore" action to minimize the risk of exploitation.

Exploit

Fix

Related Identifiers

CVE-2022-3900

Affected Products

Cooked Pro Wordpress Plugin