
Cloud Vulnerability DB
A community-led vulnerabilities database
The SEOPress WordPress plugin before version 7.8 contains an open redirect vulnerability identified as CVE-2024-4900. The vulnerability was discovered by Dmitrii Ignatyev and publicly disclosed on June 3, 2024. This security issue affects the WordPress plugin wp-seopress and can be exploited by users with contributor-level permissions or higher (WPScan).
The vulnerability stems from improper validation and escaping of Post settings within the plugin. It has been assigned a CVSS score of 2.7 (low severity) and is classified as a CWE-601 type vulnerability. The issue falls under the OWASP Top 10 category A1: Injection (WPScan).
When exploited, this vulnerability allows attackers with contributor or higher role permissions to perform open redirect attacks against any user viewing a malicious post. This means that unsuspecting users can be redirected to potentially malicious websites when viewing compromised content (WPScan).
A proof of concept exists demonstrating the vulnerability's exploitation. An attacker with contributor access can create a new Post and insert a malicious payload in the Social > Facebook Title field. When users preview or view the post, they will be automatically redirected to the attacker-specified URL (WPScan).
The vulnerability has been fixed in SEOPress version 7.8. Users are advised to update their SEOPress WordPress plugin to this version or later to mitigate the risk (WPScan).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."