CVE-2024-4900: SEOPress < 7.8 - Contributor+ Open Redirect
The SEOPress WordPress plugin before 7.8 does not validate and escape one of its Post settings, which could allow contributor and above role to perform Open redirect attacks against any user viewing a malicious post
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4900?
CVE-2024-4900 is classified as a medium severity vulnerability due to its potential for exploitation through open redirect attacks.
How do I fix CVE-2024-4900?
To fix CVE-2024-4900, update the SEOPress WordPress plugin to version 7.8 or later.
Who is affected by CVE-2024-4900?
Users with contributor or higher roles in WordPress sites using the affected versions of the SEOPress plugin are at risk from CVE-2024-4900.
What type of attack can CVE-2024-4900 facilitate?
CVE-2024-4900 can facilitate open redirect attacks, allowing attackers to redirect users to malicious sites.
Is there a workaround for CVE-2024-4900?
A temporary workaround for CVE-2024-4900 is to restrict user roles that have permission to modify the affected Post settings until the plugin is updated.