CVE-2024-5488

Scores

EPSS

0.710medium71.0%
0%20%40%60%80%100%

Percentile: 71.0%

CVSS

9.8critical3.x
0246810

CVSS Score: 9.8/10

All CVSS Scores

CVSS 3.x
9.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

The SEOPress WordPress plugin before 7.9 does not properly protect some of its REST API routes, which combined with another Object Injection vulnerability can allow unauthenticated attackers to unserialize malicious gadget chains, compromising the site if a suitable chain is present.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

anchore_overridesnvd

CWEs

CWE-502

Related Vulnerabilities

Vulnerable Software (2)

Type: Configuration

Operating System:

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:a:seopress:seopress:*:*:*:*:*:wordpress:*:*",          "versionEndExcluding": "7.9"        }      ],      "neg...

Source: anchore_overrides

Type: Configuration

Vendor: *

Product: seopress

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:seopress:seopress:*:*:*:*:*:wordpress:*:*",      "versionEndExcluding": "7.9",      "vulnerable": true    }  ],  "operator": "OR"}

Source: nvd

End of list