WordPress ProfilePress Plugin <= 4.3.2 is vulnerable to PHP Object Injection
CVE-2022-45083
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 19 January 2024
What is CVE-2022-45083?
A deserialization of untrusted data vulnerability exists in the ProfilePress Membership Team Paid Membership Plugin, which can potentially allow an attacker to manipulate serialized data. This vulnerability impacts multiple functionalities including the Paid Membership Plugin, Ecommerce capabilities, User Registration Form, Login Form, User Profile services, and Restrict Content features. Exploiting this vulnerability could lead to unauthorized access or altered user data, necessitating prompt updates and security measures to safeguard sensitive information and ensure user trust.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content β ProfilePress <= 4.3.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved