CVE-2022-45083 MEDIUM

CVE-2022-45083: WordPress ProfilePress Plugin <= 4.3.2 is vulnerable to PHP Object Injection

Vendor Profilepress Membership Team
Product Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress
Weakness CWE-502 · Unsafe deserialization
Published January 19, 2024
Last update April 28, 2026

CVSS base score

6.6/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L

What the vulnerability does

01Description

Deserialization of Untrusted Data vulnerability in ProfilePress Membership Team Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress.This issue affects Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress: from n/a through 4.3.2.

Explanation of Vulnerability in Simple Terms

02Summary

ProfilePress versions up to 4.3.2 contain a deserialization vulnerability in how they process untrusted data. An authenticated administrator can craft malicious serialized input that causes the plugin to deserialize and execute arbitrary code. This affects confidentiality, integrity, and availability of the site. Update to a version newer than 4.3.2.

What an attacker can do

03Attacker Capabilities

Execute arbitrary code on the site by submitting malicious serialized data.

Potential impact on your site

04Site Impact

A compromised admin account can run arbitrary code, potentially leading to full site takeover.

Conditions required to exploit

05Prerequisites

Attacker must have administrator-level access to the WordPress site.

Key dates

06Disclosure timeline

January 19, 2024 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE