The SEOPress WordPress plugin before 7.9 does not properly protect some of its REST API routes, which combined with another Object Injection vulnerability can allow unauthenticated attackers to unserialize malicious gadget chains, compromising the site if a suitable chain is present.
History

Wed, 21 May 2025 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Seopress
Seopress seopress
Weaknesses CWE-502
CPEs cpe:2.3:a:seopress:seopress:*:*:*:*:*:wordpress:*:*
Vendors & Products Seopress
Seopress seopress

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2024-07-09T06:00:04.275Z

Updated: 2024-08-01T21:11:12.790Z

Reserved: 2024-05-29T19:54:52.736Z

Link: CVE-2024-5488

cve-icon Vulnrichment

Updated: 2024-08-01T21:11:12.790Z

cve-icon NVD

Status : Analyzed

Published: 2024-07-09T06:15:03.030

Modified: 2025-05-21T19:11:24.140

Link: CVE-2024-5488

cve-icon Redhat

No data.