Vulnerability Details CVE-2024-5488
The SEOPress WordPress plugin before 7.9 does not properly protect some of its REST API routes, which combined with another Object Injection vulnerability can allow unauthenticated attackers to unserialize malicious gadget chains, compromising the site if a suitable chain is present.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.63
EPSS Ranking 98.3%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2024-5488
-
cpe:2.3:a:seopress:seopress:-
-
cpe:2.3:a:seopress:seopress:5.0.0
-
cpe:2.3:a:seopress:seopress:5.0.1
-
cpe:2.3:a:seopress:seopress:5.0.2
-
cpe:2.3:a:seopress:seopress:5.0.3
-
cpe:2.3:a:seopress:seopress:5.0.4
-
cpe:2.3:a:seopress:seopress:5.1
-
cpe:2.3:a:seopress:seopress:5.2
-
cpe:2.3:a:seopress:seopress:5.3
-
cpe:2.3:a:seopress:seopress:5.3.1
-
cpe:2.3:a:seopress:seopress:5.4.1
-
cpe:2.3:a:seopress:seopress:5.4.2
-
cpe:2.3:a:seopress:seopress:5.4.3
-
cpe:2.3:a:seopress:seopress:5.4.4
-
cpe:2.3:a:seopress:seopress:5.5
-
cpe:2.3:a:seopress:seopress:5.5.1
-
cpe:2.3:a:seopress:seopress:5.6
-
cpe:2.3:a:seopress:seopress:5.7
-
cpe:2.3:a:seopress:seopress:5.7.1
-
cpe:2.3:a:seopress:seopress:5.7.2
-
cpe:2.3:a:seopress:seopress:5.7.3
-
cpe:2.3:a:seopress:seopress:5.8
-
cpe:2.3:a:seopress:seopress:5.8.0.1
-
cpe:2.3:a:seopress:seopress:5.8.0.2
-
cpe:2.3:a:seopress:seopress:5.8.0.3
-
cpe:2.3:a:seopress:seopress:5.8.0.4
-
cpe:2.3:a:seopress:seopress:5.8.0.5
-
cpe:2.3:a:seopress:seopress:5.9
-
cpe:2.3:a:seopress:seopress:5.9.0.1
-
cpe:2.3:a:seopress:seopress:5.9.0.2
-
cpe:2.3:a:seopress:seopress:5.9.0.3
-
cpe:2.3:a:seopress:seopress:5.9.0.4
-
cpe:2.3:a:seopress:seopress:6.0
-
cpe:2.3:a:seopress:seopress:6.0.1
-
cpe:2.3:a:seopress:seopress:6.0.2
-
cpe:2.3:a:seopress:seopress:6.1
-
cpe:2.3:a:seopress:seopress:6.1.1
-
cpe:2.3:a:seopress:seopress:6.1.2
-
cpe:2.3:a:seopress:seopress:6.2
-
cpe:2.3:a:seopress:seopress:6.2.0.1
-
cpe:2.3:a:seopress:seopress:6.2.0.2
-
cpe:2.3:a:seopress:seopress:6.3
-
cpe:2.3:a:seopress:seopress:6.3.1
-
cpe:2.3:a:seopress:seopress:6.3.2
-
cpe:2.3:a:seopress:seopress:6.4
-
cpe:2.3:a:seopress:seopress:6.4.0.1
-
cpe:2.3:a:seopress:seopress:6.4.0.2
-
cpe:2.3:a:seopress:seopress:6.5
-
cpe:2.3:a:seopress:seopress:6.5.0.1
-
cpe:2.3:a:seopress:seopress:6.5.0.2
-
cpe:2.3:a:seopress:seopress:6.5.0.3
-
cpe:2.3:a:seopress:seopress:6.6
-
cpe:2.3:a:seopress:seopress:6.6.1
-
cpe:2.3:a:seopress:seopress:6.6.2
-
cpe:2.3:a:seopress:seopress:6.6.3
-
cpe:2.3:a:seopress:seopress:6.7
-
cpe:2.3:a:seopress:seopress:6.7.1
-
cpe:2.3:a:seopress:seopress:6.7.2
-
cpe:2.3:a:seopress:seopress:6.8
-
cpe:2.3:a:seopress:seopress:6.8.0.1
-
cpe:2.3:a:seopress:seopress:6.9
-
cpe:2.3:a:seopress:seopress:6.9.1
-
cpe:2.3:a:seopress:seopress:7.0
-
cpe:2.3:a:seopress:seopress:7.0.1
-
cpe:2.3:a:seopress:seopress:7.0.2
-
cpe:2.3:a:seopress:seopress:7.0.3
-
cpe:2.3:a:seopress:seopress:7.1
-
cpe:2.3:a:seopress:seopress:7.1.1
-
cpe:2.3:a:seopress:seopress:7.1.2
-
cpe:2.3:a:seopress:seopress:7.2
-
cpe:2.3:a:seopress:seopress:7.3
-
cpe:2.3:a:seopress:seopress:7.3.1
-
cpe:2.3:a:seopress:seopress:7.3.2
-
cpe:2.3:a:seopress:seopress:7.4
-
cpe:2.3:a:seopress:seopress:7.4.1
-
cpe:2.3:a:seopress:seopress:7.5
-
cpe:2.3:a:seopress:seopress:7.5.0.1
-
cpe:2.3:a:seopress:seopress:7.5.0.2
-
cpe:2.3:a:seopress:seopress:7.5.0.3
-
cpe:2.3:a:seopress:seopress:7.5.1
-
cpe:2.3:a:seopress:seopress:7.5.2
-
cpe:2.3:a:seopress:seopress:7.5.2.1
-
cpe:2.3:a:seopress:seopress:7.6
-
cpe:2.3:a:seopress:seopress:7.6.1
-
cpe:2.3:a:seopress:seopress:7.7
-
cpe:2.3:a:seopress:seopress:7.7.1
-
cpe:2.3:a:seopress:seopress:7.7.2
-
cpe:2.3:a:seopress:seopress:7.8