CVE · Medium

CVE-2024-47299 — Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode [coming-soon] < 6.18.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-47299 Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode [coming-soon] < 6.18.4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.9 < 6.18.4 6.18.4 2024-09-24

CVE-2024-47299

The Website Builder by SeedProd plugin through version 6.17.4 contains a stored cross-site scripting vulnerability caused by inadequate sanitization of inputs and escaping of outputs. Authenticated users with editor-level permissions can inject malicious scripts into pages that execute when other users view those pages. This vulnerability only impacts WordPress multisite installations or setups where the unfiltered_html capability has been restricted. The flaw is addressed in version 6.18.4 and later.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.