← Back to browse · API

CVE-2022-3900

Severity
CRITICAL
CVSS
9.8
EPSS
0.18966
Risk score
45.84
CISA KEV
No
PoC
No
Published
2022-12-12
Modified
2025-04-22
First seen
2026-08-07
Aliases
EUVD-2022-43236, GHSA-GX5Q-2VPF-G2W4
Products
Gora Tech LLC:Cooked Pro 0 <1.7.5.7
Sources
euvd EUVD-2022-43236

Description

The Cooked Pro WordPress plugin before 1.7.5.7 does not properly validate or sanitize the recipe_args parameter before unserializing it in the cooked_loadmore action, allowing an unauthenticated attacker to trigger a PHP Object injection vulnerability.

References