The SEOPress WordPress plugin before 7.9 does not properly protect some of its REST API routes, which combined with another Object Injection vulnerability can allow unauthenticated attackers to unserialize malicious gadget chains, compromising the site if a suitable chain is present.
Metrics
Affected Vendors & Products
References
History
Wed, 21 May 2025 19:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Seopress
Seopress seopress |
|
Weaknesses | CWE-502 | |
CPEs | cpe:2.3:a:seopress:seopress:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Seopress
Seopress seopress |

Status: PUBLISHED
Assigner: WPScan
Published: 2024-07-09T06:00:04.275Z
Updated: 2024-08-01T21:11:12.790Z
Reserved: 2024-05-29T19:54:52.736Z
Link: CVE-2024-5488

Updated: 2024-08-01T21:11:12.790Z

Status : Analyzed
Published: 2024-07-09T06:15:03.030
Modified: 2025-05-21T19:11:24.140
Link: CVE-2024-5488

No data.