PT-2024-4398 · WordPress · Seopress
Marc Montpas
·
Published
2024-06-18
·
Updated
2024-07-11
·
CVE-2024-5488
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SEOPress versions prior to 7.9
Description
The issue is related to insufficient protection of some REST API routes in the SEOPress WordPress plugin, which can be combined with an Object Injection vulnerability to allow unauthenticated attackers to unserialize malicious gadget chains. This can compromise the site if a suitable chain is present. The vulnerability is also related to flaws in the deserialization mechanism, which can allow a remote attacker to execute arbitrary commands in the web console.
Recommendations
For versions prior to 7.9, update to version 7.9 or later to resolve the issue. As a temporary workaround, consider restricting access to the REST API routes until a patch is available. Avoid using the vulnerable Object Injection functionality in the SEOPress plugin until the issue is resolved.
Exploit
Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Seopress