The SEOPress WordPress plugin before 6.5.0.3 unserializes user input provided via the settings, which could allow high-privilege users such as admin to perform PHP Object Injection when a suitable gadget is present.
References
| Link | Resource |
|---|---|
| https://wpscan.com/vulnerability/fb8791f5-2879-431e-9afc-06d5839e4b9d | Exploit Third Party Advisory |
| https://wpscan.com/vulnerability/fb8791f5-2879-431e-9afc-06d5839e4b9d | Exploit Third Party Advisory |
Configurations
History
30 Jan 2025, 15:15
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-502 |
21 Nov 2024, 07:39
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://wpscan.com/vulnerability/fb8791f5-2879-431e-9afc-06d5839e4b9d - Exploit, Third Party Advisory |
07 Nov 2023, 04:04
| Type | Values Removed | Values Added |
|---|---|---|
| CWE |
08 May 2023, 17:59
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.2 |
| First Time |
Seopress
Seopress seopress |
|
| References | (MISC) https://wpscan.com/vulnerability/fb8791f5-2879-431e-9afc-06d5839e4b9d - Exploit, Third Party Advisory | |
| CPE | cpe:2.3:a:seopress:seopress:*:*:*:*:*:wordpress:*:* |
02 May 2023, 08:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2023-05-02 08:15
Updated : 2025-01-30 15:15
NVD link : CVE-2023-1669
Mitre link : CVE-2023-1669
CVE.ORG link : CVE-2023-1669
JSON object : View
Products Affected
seopress
- seopress
CWE
CWE-502
Deserialization of Untrusted Data
