WordPress ProfilePress Plugin <= 4.3.2 is vulnerable to PHP Object Injection
CVE-2022-45083

7.2HIGH

Summary

A deserialization of untrusted data vulnerability exists in the ProfilePress Membership Team Paid Membership Plugin, which can potentially allow an attacker to manipulate serialized data. This vulnerability impacts multiple functionalities including the Paid Membership Plugin, Ecommerce capabilities, User Registration Form, Login Form, User Profile services, and Restrict Content features. Exploiting this vulnerability could lead to unauthorized access or altered user data, necessitating prompt updates and security measures to safeguard sensitive information and ensure user trust.

Affected Version(s)

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.3.2

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

MgThuraMoeMyint (Patchstack Alliance)
.