CVE-2024-5488
The SEOPress plugin through version 7.8 contains a PHP Object Injection vulnerability stemming from unsafe deserialization of the 'title' parameter, allowing unauthenticated attackers to introduce malicious PHP objects into the system. While the plugin itself lacks a functional POP chain for exploitation, the presence of such a chain in other installed plugins or themes could enable an attacker to perform arbitrary file deletion, access confidential information, or achieve remote code execution. The vulnerability affects all versions up to and including 7.8, with a fix available in version 7.9 and later.
Based on public CVE data (MITRE/NVD).