Junglewise Threat Intelligence

CVE-2025-14785: SeedProd Website Builder Stored XSS in seedprodnestedmenuwidget shortcode

CVE-2025-14785 · Severity: medium · CVSS 6.4 · Published 2026-07-08

Executive brief

SeedProd Website Builder, a popular WordPress plugin used for creating landing pages and maintenance mode screens, contains a security flaw that allows users with contributor-level access to inject malicious scripts into website pages. When other users or visitors view these affected pages, the scripts will execute in their browsers. This could lead to unauthorized actions being performed on behalf of site administrators or the theft of sensitive session information.

Technical details

The SeedProd Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on user-supplied attributes within the 'seedprodnestedmenuwidget' shortcode. This vulnerability exists in all versions up to and including 6.20.2. An authenticated attacker with at least contributor-level permissions can exploit this by embedding malicious web scripts into a page via the shortcode. Because the input is stored and later rendered without proper security filtering, the script executes in the context of any user (including administrators) who views the affected page. A patch appears to have been addressed in subsequent updates (changeset 3565979).

Affected products

  • SeedProd Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode up to, and including, 6.20.2

Timeline

  • 2026-07-08: disclosed
  • 2026-07-08: advisory

References