ZeroHour

CVE-2024-4900

PoC
CVSS 3.1
6.1 medium
EPSS
<1%p26
Published
()
Modified
Description

The SEOPress WordPress plugin before 7.8 does not validate and escape one of its Post settings, which could allow contributor and above role to perform Open redirect attacks against any user viewing a malicious post

Vendors
seopress
Products
seopress
Ecosystems
WordPress
Weakness
CWE-601
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.