First published: Mon Feb 05 2024(Updated: )
The Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the seedprod_lite_new_lpage function in all versions up to, and including, 6.15.21. This makes it possible for unauthenticated attackers to change the contents of coming-soon, maintenance pages, login and 404 pages set up with the plugin. Version 6.15.22 addresses this issue but introduces a bug affecting admin pages. We suggest upgrading to 6.15.23.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
SeedProd Website Builder | <=6.15.21 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-1072 has a moderate severity level due to potential unauthorized data modification risks.
To fix CVE-2024-1072, update the Website Builder by SeedProd plugin to the latest version beyond 6.15.21.
CVE-2024-1072 affects users of the SeedProd Website Builder plugin for WordPress in all versions up to and including 6.15.21.
CVE-2024-1072 is a data modification vulnerability resulting from a missing capability check.
Yes, a patch is available in the newer releases of the SeedProd Website Builder plugin.