CVE-2024-4900
PoC —CVSS 3.1
6.1 medium
EPSS
<1%p26
Published
()
Modified
Description
The SEOPress WordPress plugin before 7.8 does not validate and escape one of its Post settings, which could allow contributor and above role to perform Open redirect attacks against any user viewing a malicious post
- Vendors
- seopress
- Products
- seopress
- Ecosystems
- WordPress
- Weakness
- CWE-601
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.