CVE-2025-24540: WordPress Website Builder by SeedProd plugin <= 6.18.9 - Cross Site Request Forgery (CSRF) vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in SeedProd Coming Soon Page, Under Construction & Maintenance Mode by SeedProd coming-soon allows Cross Site Request Forgery.This issue affects Coming Soon Page, Under Construction & Maintenance Mode by SeedProd: from n/a through <= 6.18.9.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24540?
CVE-2025-24540 is a Cross-Site Request Forgery (CSRF) vulnerability that can potentially allow unauthorized actions to be performed on behalf of victims.
How do I fix CVE-2025-24540?
To fix CVE-2025-24540, users should update the SeedProd Coming Soon Page, Under Construction & Maintenance Mode plugin to version 6.18.10 or later.
Which versions are affected by CVE-2025-24540?
CVE-2025-24540 affects versions of SeedProd Coming Soon Page, Under Construction & Maintenance Mode from n/a up to and including 6.18.9.
What software does CVE-2025-24540 impact?
CVE-2025-24540 impacts the SeedProd Coming Soon Page, Under Construction & Maintenance Mode plugin as well as the SeedProd WordPress Website Builder.
Is CVE-2025-24540 a critical vulnerability?
While CVE-2025-24540 poses a risk due to its CSRF nature, its criticality depends on the specific usage and configurations of the affected plugins.