WordPress Plugin Vulnerabilities

SEOPress < 7.9 - Unauthenticated Object Injection

Description

The plugin does not properly protect some of its REST API routes, which combined with another Object Injection vulnerability can allow unauthenticated attackers to unserialize malicious gadget chains, compromising the site if a suitable chain is present.

Proof of Concept

Affects Plugins

Fixed in 7.9

References

Classification

Type
OBJECT INJECTION
CWE
CVSS

Miscellaneous

Original Researcher
Marc Montpas
Submitter
Marc Montpas
Submitter website
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2024-06-18 (about 1 year ago)
Added
2024-06-18 (about 1 year ago)
Last Updated
2024-06-25 (about 1 year ago)

Other