CVE-2022-3900

Published: Dic 12, 2022 Last Modified: Apr 22, 2025
ExploitDB:
Other exploit source:
Google Dorks:
CRITICAL 9,8
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: high
Integrity: high
Availability: high

Description

AI Translation Available

The Cooked Pro WordPress plugin before 1.7.5.7 does not properly validate or sanitize the recipe_args parameter before unserializing it in the cooked_loadmore action, allowing an unauthenticated attacker to trigger a PHP Object injection vulnerability.

EPSS (Exploit Prediction Scoring System)

Trend Analysis

EPSS (Exploit Prediction Scoring System)

Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.

EPSS Score
0,1781
Percentile
0,9th
Updated

EPSS Score Trend (Last 90 Days)

Application

Cooked by Boxystudio

Version Range Affected
To 1.7.5.7 (exclusive)
cpe:2.3:a:boxystudio:cooked:*:*:*:*:pro:wordpress:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://wpscan.com/vulnerability/c969c4bc-82d7-46a0-88ba-e056c0b27de7
https://wpscan.com/vulnerability/c969c4bc-82d7-46a0-88ba-e056c0b27de7