Executive brief
SeedProd Pro is a popular WordPress plugin used for creating landing pages and 'coming soon' pages. A security vulnerability allows users with 'Contributor' level access to inject malicious scripts into the website. If an administrator views the affected content, these scripts could execute, potentially leading to unauthorized site changes, redirection of visitors to malicious websites, or theft of administrative session information.
Technical details
A Cross-Site Scripting (XSS) vulnerability exists in SeedProd Pro versions prior to 6.19.5 due to improper neutralization of input during web page generation (CWE-79). The flaw allows an authenticated attacker with 'Contributor' privileges to inject arbitrary JavaScript into pages or posts. Because the vulnerability is 'Stored' and has a 'Changed' scope (S:C), the script executes in the context of other users, such as administrators, when they view the malicious content. Exploitation requires the attacker to have network access to the WordPress backend and necessitates interaction from a victim (UI:R). The issue is resolved in version 6.19.5.
Affected products
- SeedProd LLC. SeedProd Pro < 6.19.5
Timeline
- 2025-10-25: other: Vulnerability reported by researcher João Pedro S Alcântara
- 2026-06-25: advisory: Patchstack published advisory and early warning
- 2026-06-26: disclosed: NVD published CVE record