PoC Index

CVE-2024-5488

CRITICAL 9.8EPSS 3.7%

The SEOPress WordPress plugin before 7.9 does not properly protect some of its REST API routes, which combined with another Object Injection vulnerability can allow unauthenticated attackers to unserialize malicious gadget chains, compromising the site if a suitable chain is present.

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
3.74% chance of exploitation in the next 30 days, 89th percentile
Nuclei
critical
Published
2024-07-09
Updated
2024-08-01

Proof-of-concept exploits (1)

Nuclei templates (1)

References

Related