CVE-2022-3900

CVE-2022-3900: Cooked Pro < 1.7.5.7 - Unauthenticated PHP Object Injection

Vendor Unknown
Product Cooked Pro
Published December 12, 2022
Last update April 22, 2025

CVSS base score

What the vulnerability does

01Description

The Cooked Pro WordPress plugin before 1.7.5.7 does not properly validate or sanitize the recipe_args parameter before unserializing it in the cooked_loadmore action, allowing an unauthenticated attacker to trigger a PHP Object injection vulnerability.

Key dates

02Disclosure timeline

December 12, 2022 CVE published
April 22, 2025 Record updated