First published: Wed Jun 24 2020(Updated: )
The SeedProd coming-soon plugin before 5.1.1 for WordPress allows XSS.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SeedProd Coming Soon Page, Under Construction & Maintenance Mode | <5.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-15038 is a vulnerability in the SeedProd coming-soon plugin before version 5.1.1 for WordPress that allows XSS (Cross-Site Scripting).
The severity of CVE-2020-15038 is medium, with a severity value of 5.4.
If you are using the SeedProd coming-soon plugin before version 5.1.1 for WordPress, you may be vulnerable to XSS attacks.
To fix CVE-2020-15038, you should update the SeedProd coming-soon plugin to version 5.1.1 or higher.
You can find more information about CVE-2020-15038 at the following references: - http://packetstormsecurity.com/files/158649/WordPress-Maintenance-Mode-By-SeedProd-5.1.1-Cross-Site-Scripting.html - https://wordpress.org/plugins/coming-soon/#developers - https://wpvulndb.com/vulnerabilities/10283