CVE · Medium

CVE-2024-4900 — SEOPress – AI SEO Plugin & On-site SEO [wp-seopress] < 7.8

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-4900 SEOPress – AI SEO Plugin & On-site SEO [wp-seopress] < 7.8 URL Redirection to Untrusted Site ('Open Redirect') Medium 6.1 < 7.8 7.8 2024-06-03

CVE-2024-4900

The SEOPress plugin for WordPress contains an open redirect vulnerability in versions 7.7.2 and earlier that stems from inadequate validation of the social post settings feature. An attacker with at least contributor-level permissions can exploit this flaw to redirect users to external malicious websites, provided the victim can be deceived into clicking a crafted link or performing a specific action. The vulnerability requires authenticated access to the WordPress environment to be exploited.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.