CVE-2022-45083: WordPress ProfilePress Plugin <= 4.3.2 is vulnerable to PHP Object Injection
Deserialization of Untrusted Data vulnerability in ProfilePress Membership Team Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress.This issue affects Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress: from n/a through 4.3.2.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2022-45083?
CVE-2022-45083 has been classified as a critical severity vulnerability due to its potential impact on the affected systems.
How do I fix CVE-2022-45083?
To remediate CVE-2022-45083, upgrade the ProfilePress plugin to version 4.4.0 or later.
What versions of ProfilePress are affected by CVE-2022-45083?
CVE-2022-45083 affects all versions of the ProfilePress plugin prior to version 4.4.0.
What type of vulnerability is CVE-2022-45083?
CVE-2022-45083 is a Deserialization of Untrusted Data vulnerability.
Who is affected by CVE-2022-45083?
Users of the ProfilePress Membership Team Paid Membership Plugin and related applications are affected by CVE-2022-45083.