Seedprod · Website Builder · CVE-2025-14785
**Name of the Vulnerable Software and Affected Versions**
Website Builder by SeedProd - Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode versions prior to 6.20.3
**Description**
Stored Cross-Site Scripting occurs due to insufficient input sanitization and output escaping on user supplied attributes within the `seedprodnestedmenuwidget` shortcode. This allows authenticated attackers with contributor level access and above to inject arbitrary web scripts into pages, which execute when a user accesses the affected page.
**Recommendations**
Update to a version newer than 6.20.2.