CVE-2024-5488

CRITICAL NUCLEI

SEOPress < 7.9 - Unauthenticated Deserialization of Untrusted Data via REST API

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2024-5488 has a Nuclei detection template available — see the Nuclei card below for the Shodan/FOFA recon queries.

Description

The SEOPress WordPress plugin before 7.9 does not properly protect some of its REST API routes, which combined with another Object Injection vulnerability can allow unauthenticated attackers to unserialize malicious gadget chains, compromising the site if a suitable chain is present.

Nuclei Templates (1)

SEOPress < 7.9 - Authentication Bypass
CRITICALVERIFIEDby pdresearch,iamnoooob,rootxharsh

References (1)

Core 1
Core References
Exploit, Third Party Advisory exploit vdb-entry technical-description
https://wpscan.com/vulnerability/28507376-ded0-4e1a-b2fc-2182895aa14c/

Scores

CVSS v3 9.8
EPSS 0.0377
EPSS Percentile 88.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-502
Status published
Products (1)
seopress/seopress < 7.9
Published Jul 09, 2024
Tracked Since Feb 18, 2026