First published: Mon Jan 27 2025(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in SeedProd Coming Soon Page, Under Construction & Maintenance Mode by SeedProd allows Cross Site Request Forgery. This issue affects Coming Soon Page, Under Construction & Maintenance Mode by SeedProd: from n/a through 6.18.9.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
SeedProd Coming Soon Page, Under Construction & Maintenance Mode | <=6.18.9 | |
SeedProd Website Builder | <=6.18.9 |
Update the WordPress Coming Soon Page, Under Construction & Maintenance Mode by SeedProd plugin to the latest available version (at least 6.18.10).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-24540 is a Cross-Site Request Forgery (CSRF) vulnerability that can potentially allow unauthorized actions to be performed on behalf of victims.
To fix CVE-2025-24540, users should update the SeedProd Coming Soon Page, Under Construction & Maintenance Mode plugin to version 6.18.10 or later.
CVE-2025-24540 affects versions of SeedProd Coming Soon Page, Under Construction & Maintenance Mode from n/a up to and including 6.18.9.
CVE-2025-24540 impacts the SeedProd Coming Soon Page, Under Construction & Maintenance Mode plugin as well as the SeedProd WordPress Website Builder.
While CVE-2025-24540 poses a risk due to its CSRF nature, its criticality depends on the specific usage and configurations of the affected plugins.