CVE-2024-5488

The SEOPress WordPress plugin before 7.9 does not properly protect some of its REST API routes, which combined with another Object Injection vulnerability can allow unauthenticated attackers to unserialize malicious gadget chains, compromising the site if a suitable chain is present.
Configurations

Configuration 1 (hide)

cpe:2.3:a:seopress:seopress:*:*:*:*:*:wordpress:*:*

History

21 May 2025, 19:11

Type Values Removed Values Added
CPE cpe:2.3:a:seopress:seopress:*:*:*:*:*:wordpress:*:*
References () https://wpscan.com/vulnerability/28507376-ded0-4e1a-b2fc-2182895aa14c/ - () https://wpscan.com/vulnerability/28507376-ded0-4e1a-b2fc-2182895aa14c/ - Exploit, Third Party Advisory
CWE CWE-502
First Time Seopress seopress
Seopress

21 Nov 2024, 09:47

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/28507376-ded0-4e1a-b2fc-2182895aa14c/ - () https://wpscan.com/vulnerability/28507376-ded0-4e1a-b2fc-2182895aa14c/ -

11 Jul 2024, 15:06

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

09 Jul 2024, 18:19

Type Values Removed Values Added
Summary
  • (es) El complemento SEOPress WordPress anterior a 7.9 no protege adecuadamente algunas de sus rutas API REST, lo que combinado con otra vulnerabilidad de inyección de objetos puede permitir a atacantes no autenticados deserializar cadenas de dispositivos maliciosos, comprometiendo el sitio si hay una cadena adecuada presente.

09 Jul 2024, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-09 06:15

Updated : 2025-05-21 19:11


NVD link : CVE-2024-5488

Mitre link : CVE-2024-5488

CVE.ORG link : CVE-2024-5488


JSON object : View

Products Affected

seopress

  • seopress
CWE
CWE-502

Deserialization of Untrusted Data