Vulnerability Details CVE-2024-5488
The SEOPress WordPress plugin before 7.9 does not properly protect some of its REST API routes, which combined with another Object Injection vulnerability can allow unauthenticated attackers to unserialize malicious gadget chains, compromising the site if a suitable chain is present.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.038
EPSS Ranking 88.5%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2024-5488
-
cpe:2.3:a:seopress:seopress:-
-
cpe:2.3:a:seopress:seopress:5.0.0
-
cpe:2.3:a:seopress:seopress:5.0.1
-
cpe:2.3:a:seopress:seopress:5.0.2
-
cpe:2.3:a:seopress:seopress:5.0.3
-
cpe:2.3:a:seopress:seopress:5.0.4
-
cpe:2.3:a:seopress:seopress:5.1
-
cpe:2.3:a:seopress:seopress:5.2
-
cpe:2.3:a:seopress:seopress:5.3
-
cpe:2.3:a:seopress:seopress:5.3.1
-
cpe:2.3:a:seopress:seopress:5.4.1
-
cpe:2.3:a:seopress:seopress:5.4.2
-
cpe:2.3:a:seopress:seopress:5.4.3
-
cpe:2.3:a:seopress:seopress:5.4.4
-
cpe:2.3:a:seopress:seopress:5.5
-
cpe:2.3:a:seopress:seopress:5.5.1
-
cpe:2.3:a:seopress:seopress:5.6
-
cpe:2.3:a:seopress:seopress:5.7
-
cpe:2.3:a:seopress:seopress:5.7.1
-
cpe:2.3:a:seopress:seopress:5.7.2
-
cpe:2.3:a:seopress:seopress:5.7.3
-
cpe:2.3:a:seopress:seopress:5.8
-
cpe:2.3:a:seopress:seopress:5.8.0.1
-
cpe:2.3:a:seopress:seopress:5.8.0.2
-
cpe:2.3:a:seopress:seopress:5.8.0.3
-
cpe:2.3:a:seopress:seopress:5.8.0.4
-
cpe:2.3:a:seopress:seopress:5.8.0.5
-
cpe:2.3:a:seopress:seopress:5.9
-
cpe:2.3:a:seopress:seopress:5.9.0.1
-
cpe:2.3:a:seopress:seopress:5.9.0.2
-
cpe:2.3:a:seopress:seopress:5.9.0.3
-
cpe:2.3:a:seopress:seopress:5.9.0.4
-
cpe:2.3:a:seopress:seopress:6.0
-
cpe:2.3:a:seopress:seopress:6.0.1
-
cpe:2.3:a:seopress:seopress:6.0.2
-
cpe:2.3:a:seopress:seopress:6.1
-
cpe:2.3:a:seopress:seopress:6.1.1
-
cpe:2.3:a:seopress:seopress:6.1.2
-
cpe:2.3:a:seopress:seopress:6.2
-
cpe:2.3:a:seopress:seopress:6.2.0.1
-
cpe:2.3:a:seopress:seopress:6.2.0.2
-
cpe:2.3:a:seopress:seopress:6.3
-
cpe:2.3:a:seopress:seopress:6.3.1
-
cpe:2.3:a:seopress:seopress:6.3.2
-
cpe:2.3:a:seopress:seopress:6.4
-
cpe:2.3:a:seopress:seopress:6.4.0.1
-
cpe:2.3:a:seopress:seopress:6.4.0.2
-
cpe:2.3:a:seopress:seopress:6.5
-
cpe:2.3:a:seopress:seopress:6.5.0.1
-
cpe:2.3:a:seopress:seopress:6.5.0.2
-
cpe:2.3:a:seopress:seopress:6.5.0.3
-
cpe:2.3:a:seopress:seopress:6.6
-
cpe:2.3:a:seopress:seopress:6.6.1
-
cpe:2.3:a:seopress:seopress:6.6.2
-
cpe:2.3:a:seopress:seopress:6.6.3
-
cpe:2.3:a:seopress:seopress:6.7
-
cpe:2.3:a:seopress:seopress:6.7.1
-
cpe:2.3:a:seopress:seopress:6.7.2
-
cpe:2.3:a:seopress:seopress:6.8
-
cpe:2.3:a:seopress:seopress:6.8.0.1
-
cpe:2.3:a:seopress:seopress:6.9
-
cpe:2.3:a:seopress:seopress:6.9.1
-
cpe:2.3:a:seopress:seopress:7.0
-
cpe:2.3:a:seopress:seopress:7.0.1
-
cpe:2.3:a:seopress:seopress:7.0.2
-
cpe:2.3:a:seopress:seopress:7.0.3
-
cpe:2.3:a:seopress:seopress:7.1
-
cpe:2.3:a:seopress:seopress:7.1.1
-
cpe:2.3:a:seopress:seopress:7.1.2
-
cpe:2.3:a:seopress:seopress:7.2
-
cpe:2.3:a:seopress:seopress:7.3
-
cpe:2.3:a:seopress:seopress:7.3.1
-
cpe:2.3:a:seopress:seopress:7.3.2
-
cpe:2.3:a:seopress:seopress:7.4
-
cpe:2.3:a:seopress:seopress:7.4.1
-
cpe:2.3:a:seopress:seopress:7.5
-
cpe:2.3:a:seopress:seopress:7.5.0.1
-
cpe:2.3:a:seopress:seopress:7.5.0.2
-
cpe:2.3:a:seopress:seopress:7.5.0.3
-
cpe:2.3:a:seopress:seopress:7.5.1
-
cpe:2.3:a:seopress:seopress:7.5.2
-
cpe:2.3:a:seopress:seopress:7.5.2.1
-
cpe:2.3:a:seopress:seopress:7.6
-
cpe:2.3:a:seopress:seopress:7.6.1
-
cpe:2.3:a:seopress:seopress:7.7
-
cpe:2.3:a:seopress:seopress:7.7.1
-
cpe:2.3:a:seopress:seopress:7.7.2
-
cpe:2.3:a:seopress:seopress:7.8