Description
It was determined that your web application is performing PHP object deserialization of user-supplied data. Arbitrary object deserialization is inherently unsafe, and should never be performed on untrusted data. Consult Web references section for more information about this issue.
Remediation
PHP object deserialization should not be performed on user-supplied data. Do not use the unserialize() function with user-supplied input, use JSON functions instead.
References
Related Vulnerabilities
WordPress Plugin WordPress Facebook SQL Injection (1.0.13)
WordPress Plugin myCred-Points, Rewards, Gamification, Ranks, Badges & Loyalty SQL Injection (2.2)
WordPress Plugin Xtreme Locator Dealer Locator SQL Injection (1.5)
WordPress Plugin Listing, Classified Ads & Business Directory-uListing SQL Injection (2.0.3)
WordPress Plugin Photoracer 'id' Parameter SQL Injection (1.0)