Executive brief
SeedProd Coming Soon Page is a popular WordPress plugin used to display maintenance or 'coming soon' screens while a site is under development. A security vulnerability in this plugin could allow an authorized user with high-level permissions to force the website to make unauthorized requests to internal or external servers. This could lead to the exposure of sensitive information from other services running on the same network or system.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in the SeedProd Coming Soon Page, Under Construction & Maintenance Mode plugin for WordPress (versions <= 6.19.8). The flaw allows an attacker with high privileges (such as an Editor or Administrator) to trigger the server to send arbitrary web requests. This can be used to probe internal network services or access sensitive data that is otherwise unreachable from the public internet. The issue is caused by insufficient validation of user-supplied URLs. A fix is available in version 6.19.9.
Affected products
- SeedProd Coming Soon Page, Under Construction & Maintenance Mode by SeedProd <= 6.19.8
Timeline
- 2026-02-12: other: Reported by researcher timomangcut
- 2026-03-14: advisory: Patchstack advisory published
- 2026-04-08: disclosed: CVE published to NVD
- 2026-03-14: patched: Version 6.19.9 released to address the vulnerability