Vulnerabilidades conocidas, compatibilidad con PHP y alternativas más seguras para el plugin de WordPress Coming Soon — verificado contra la base de datos de seguridad local de WP Clinic.
Qué hace este plugin
- Slug:
coming-soon
- 700000+ instalaciones activas
coming soon pagelanding pagemaintenance modepage builderwebsite builder
Estado de mantenimiento
- Última versión conocida: 6.20.5
- Requiere PHP: 5.6+
- PHP máximo soportado (analizado): <8.0
Vulnerabilidades conocidas
10 CVEs conocidos registrados para Coming Soon.
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
CVE-2025-14785
|
Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode [coming-soon] < 6.20.3 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,4
|
< 6.20.3
|
6.20.3 |
2026-07-07 |
✓ corregido en la última versión
|
|
CVE-2026-39464
|
Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode [coming-soon] < 6.19.9 |
— |
Media
5,5
|
< 6.19.9
|
6.19.9 |
2026-03-14 |
✓ corregido en la última versión
|
|
CVE-2026-27368
|
Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode [coming-soon] < 6.19.9 |
Falta de control de autorización |
Media
5,3
|
< 6.19.9
|
6.19.9 |
2025-12-24 |
✓ corregido en la última versión
|
|
CVE-2025-24540
|
Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode [coming-soon] < 6.18.10 |
Falsificación de petición en sitios cruzados (CSRF) |
Media
4,3
|
< 6.18.10
|
6.18.10 |
2024-11-09 |
✓ corregido en la última versión
|
|
CVE-2024-47299
|
Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode [coming-soon] < 6.18.4 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,9
|
< 6.18.4
|
6.18.4 |
2024-09-24 |
✓ corregido en la última versión
|
|
CVE-2024-32088
|
Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode [coming-soon] < 6.15.21 |
Falsificación de petición en sitios cruzados (CSRF) |
Media
4,3
|
< 6.15.21
|
6.15.21 |
2024-04-11 |
✓ corregido en la última versión
|
|
CVE-2024-1072
|
Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode [coming-soon] < 6.15.22 |
Falta de control de autorización |
Alta
7,5
|
< 6.15.22
|
6.15.22 |
2024-02-05 |
✓ corregido en la última versión
|
|
—
|
Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode [coming-soon] < 6.15.22 |
— |
Desconocido
|
< 6.15.22
|
6.15.22 |
2024-01-31 |
✓ corregido en la última versión
|
CVE-2025-14785
The Website Builder by SeedProd - Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `seedprodnestedmenuwidget` shortcode in all versions up to, and including, 6.20.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2026-39464
The Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.19.8. This makes it possible for authenticated attackers, with Editor-level access and above, to make web requests to arbitrary locations originating from the web application which can be used to query and modify information from internal services.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2026-27368
The Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 6.19.8. This makes it possible for unauthenticated attackers to perform an unauthorized action.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2025-24540
The Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.18.9. This is due to missing or incorrect nonce validation on an unknown function. This makes it possible for unauthenticated attackers to perform an unknown action granted they can trick a site administrator into performing an action such as clicking on a link. The impact of this vulnerability is unknown.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2024-47299
The Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 6.17.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2024-32088
Update the WordPress Coming Soon Page, Under Construction & Maintenance Mode by SeedProd plugin to the latest available version (at least 6.15.21).
Dhabaleshwar Das discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Coming Soon Page, Under Construction & Maintenance Mode by SeedProd Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. This vulnerability has been fixed in version 6.15.21.
This vulnerability was reported to and published by Patchstack. Our users receive alerts and protections up to 48 hours in advance.
Have additional information or questions about this entry? Get in touch.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2024-1072
The Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the seedprod_lite_new_lpage function in all versions up to, and including, 6.15.21. This makes it possible for unauthenticated attackers to change the contents of coming-soon, maintenance pages, login and 404 pages set up with the plugin. Version 6.15.22 addresses this issue but introduces a bug affecting admin pages. We suggest upgrading to 6.15.23.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode [coming-soon] < 6.15.22
The Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the seedprod_lite_new_lpage function in all versions up to, and including, 6.15.21. This makes it possible for unauthenticated attackers to change the contents of coming-soon, maintenance pages, login and 404 pages set up with the plugin. Version 6.15.22 addresses this issue but introduces a bug affecting admin pages. We suggest upgrading to 6.15.23.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
+ 4 vulnerabilidades conocidas más
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
CVE-2023-4975
|
Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode [coming-soon] < 6.15.15.3 |
Falsificación de petición en sitios cruzados (CSRF) |
Media
4,3
|
< 6.15.15.3
|
6.15.15.3 |
2023-09-18 |
✓ corregido en la última versión
|
|
CVE-2020-15038
|
Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode [coming-soon] < 5.1.2 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 5.1.2
|
5.1.2 |
2020-06-24 |
✓ corregido en la última versión
|
|
CVE-2025-3949
|
Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode [coming-soon] < 6.18.16 |
Falta de control de autorización |
Media
4,3
|
< 6.18.16
|
6.18.16 |
0000-00-00 |
✓ corregido en la última versión
|
|
—
|
Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode [coming-soon] < 6.15.22 |
— |
Desconocido
|
< 6.15.22
|
6.15.22 |
— |
✓ corregido en la última versión
|
CVE-2023-4975
Update the WordPress Website Builder by SeedProd plugin to the latest available version (at least 6.15.15.3).
Marco Wotschka discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Coming Soon Page, Under Construction & Maintenance Mode by SeedProd Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. This vulnerability has been fixed in version 6.15.15.3.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2020-15038
Persistent Cross-Site Scripting (XSS) vulnerability found by Jinson Varghese Behanan in WordPress Coming Soon Page, Under Construction & Maintenance Mode by SeedProd plugin (versions <= 5.1.0).
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2025-3949
The Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'seedprod_lite_get_revisisons' function in all versions up to, and including, 6.18.15. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the content of arbitrary landing page revisions.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode [coming-soon] < 6.15.22
Update the WordPress Coming Soon Page, Under Construction & Maintenance Mode by SeedProd plugin to the latest available version (at least 6.15.22).
Lucio Sá discovered and reported this Broken Access Control vulnerability in WordPress Coming Soon Page, Under Construction & Maintenance Mode by SeedProd Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action. This vulnerability has been fixed in version 6.15.22.
Have additional information or questions about this entry? Get in touch.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Cómo solucionarlo
Mantén Coming Soon actualizado — 6.20.5 es la última versión en wordpress.org, y cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en").
Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.
Alternativas más seguras / más establecidas