CVE-2025-3949: Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode <= 6.18.15 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure
The Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'seedprodlitegetrevisisons' function in all versions up to, and including, 6.18.15. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the content of arbitrary landing page revisions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3949?
CVE-2025-3949 is rated as a high severity vulnerability due to the potential for unauthorized access to sensitive data.
How do I fix CVE-2025-3949?
To fix CVE-2025-3949, update the SeedProd Website Builder plugin to version 6.18.16 or later.
What data is exposed by CVE-2025-3949?
CVE-2025-3949 exposes user data through unauthorized access due to a missing capability check.
Which versions of the SeedProd Website Builder are affected by CVE-2025-3949?
CVE-2025-3949 affects all versions of the SeedProd Website Builder up to and including version 6.18.15.
Is CVE-2025-3949 exploitable remotely?
Yes, CVE-2025-3949 can be exploited remotely by attackers to gain unauthorized access to website data.