CVE-2024-1072: Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode <= 6.15.21 - Missing Authorization via seedprod_lite_new_lpage
The Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the seedprodlitenewlpage function in all versions up to, and including, 6.15.21. This makes it possible for unauthenticated attackers to change the contents of coming-soon, maintenance pages, login and 404 pages set up with the plugin. Version 6.15.22 addresses this issue but introduces a bug affecting admin pages. We suggest upgrading to 6.15.23.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode (WordPress plugin)to a version that resolves this vulnerability.Fixed in 6.15.23
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1072?
CVE-2024-1072 has a moderate severity level due to potential unauthorized data modification risks.
How do I fix CVE-2024-1072?
To fix CVE-2024-1072, update the Website Builder by SeedProd plugin to the latest version beyond 6.15.21.
Who is affected by CVE-2024-1072?
CVE-2024-1072 affects users of the SeedProd Website Builder plugin for WordPress in all versions up to and including 6.15.21.
What type of vulnerability is CVE-2024-1072?
CVE-2024-1072 is a data modification vulnerability resulting from a missing capability check.
Is there a patch for CVE-2024-1072?
Yes, a patch is available in the newer releases of the SeedProd Website Builder plugin.