WordPress Plugin Vulnerabilities

Website Builder by SeedProd < 6.15.22 - Unauthenticated Plugin Page Content Update

Description

The plugin does not have authorisation in its seedprod_lite_new_lpage function, allowing unauthenticated attackers to update the contents of coming-soon, maintenance pages, login and 404 pages set up with the plugin to a blank state

Proof of Concept

Affects Plugins

Fixed in 6.15.22

References

Classification

Type
NO AUTHORISATION
CWE

Miscellaneous

Original Researcher
Lucio Sá
Verified
Yes

Timeline

Publicly Published
2024-01-31 (about 2 years ago)
Added
2024-02-01 (about 2 years ago)
Last Updated
2024-02-01 (about 2 years ago)

Other