CVE-2024-4900
The SEOPress plugin for WordPress contains an open redirect vulnerability in versions 7.7.2 and earlier that stems from inadequate validation of the social post settings feature. An attacker with at least contributor-level permissions can exploit this flaw to redirect users to external malicious websites, provided the victim can be deceived into clicking a crafted link or performing a specific action. The vulnerability requires authenticated access to the WordPress environment to be exploited.
Based on public CVE data (MITRE/NVD).