PT-2024-16488 · Seedprod · Website Builder By Seedprod

Lucio Sá

·

Published

2024-02-01

·

Updated

2024-02-13

·

CVE-2024-1072

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
Name of the Vulnerable Software and Affected Versions Website Builder by SeedProd versions up to, and including, 6.15.21
Description The issue is related to a missing capability check on the seedprod lite new lpage function, allowing unauthenticated attackers to modify the contents of coming-soon, maintenance, login, and 404 pages set up with the plugin. It is estimated that around 900,000 WordPress sites are potentially affected.
Recommendations For versions up to, and including, 6.15.21, upgrade to version 6.15.23 to resolve the issue. As a temporary workaround, consider restricting access to the seedprod lite new lpage function until the upgrade is applied.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-1072

Affected Products

Website Builder By Seedprod