CVE · Medium

CVE-2025-14785 — Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode [coming-soon] < 6.20.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-14785 Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode [coming-soon] < 6.20.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 6.20.3 6.20.3 2026-07-07

CVE-2025-14785

The SeedProd Website Builder plugin for WordPress contains a security flaw affecting versions up to 6.20.2. The issue arises from inadequate filtering of data entered by users into the `seedprodnestedmenuwidget` shortcode, allowing malicious scripts to be embedded in pages that can run when accessed by others. This vulnerability enables authenticated users with contributor-level access or higher to inject and execute arbitrary web code on affected sites.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.