CVE-2024-5488
CRITICAL NUCLEISeopress < 7.9 - Insecure Deserialization
Title source: ruleDescription
The SEOPress WordPress plugin before 7.9 does not properly protect some of its REST API routes, which combined with another Object Injection vulnerability can allow unauthenticated attackers to unserialize malicious gadget chains, compromising the site if a suitable chain is present.
Nuclei Templates (1)
SEOPress < 7.9 - Authentication Bypass
CRITICALVERIFIEDby pdresearch,iamnoooob,rootxharsh
Scores
CVSS v3
9.8
EPSS
0.7480
EPSS Percentile
98.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-502
Status
published
Affected Products (1)
seopress/seopress
< 7.9
Timeline
Published
Jul 09, 2024
Tracked Since
Feb 18, 2026