CVE-2024-5488: SEOPress < 7.9 - Unauthenticated Object Injection
The SEOPress WordPress plugin before 7.9 does not properly protect some of its REST API routes, which combined with another Object Injection vulnerability can allow unauthenticated attackers to unserialize malicious gadget chains, compromising the site if a suitable chain is present.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5488?
CVE-2024-5488 has been identified as a critical vulnerability due to improper protection of REST API routes combined with an Object Injection issue.
How do I fix CVE-2024-5488?
To fix CVE-2024-5488, update the SEOPress WordPress plugin to version 7.9 or later.
What are the consequences of CVE-2024-5488?
The consequences of CVE-2024-5488 include the potential for unauthenticated attackers to execute code via unserialization of malicious gadget chains.
Which versions of SEOPress are affected by CVE-2024-5488?
All versions of SEOPress prior to 7.9 are affected by CVE-2024-5488.
Is CVE-2024-5488 a local or remote vulnerability?
CVE-2024-5488 is a remote vulnerability that can be exploited by unauthenticated attackers.