vendor:
Coming Soon Page, Under Construction & Maintenance Mode by SeedProd
by:
Jinson Varghese Behanan
5.4
CVSS
MEDIUM
Persistent Cross-Site Scripting
79
CWE
Product Name: Coming Soon Page, Under Construction & Maintenance Mode by SeedProd
Affected Version From: 5.1.1 and below
Affected Version To: 5.1.1
Patch Exists: YES
Related CWE: CVE-2020-15038
CPE: a:seedprod:coming_soon_page,_under_construction_&_maintenance_mode_by_seedprod
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: WordPress
2020
WordPress Plugin Maintenance Mode by SeedProd 5.1.1 – Persistent Cross-Site Scripting
Coming Soon Page, Under Construction & Maintenance Mode by SeedProd is a popular WordPress Plugin with over 1 million active installations. The Headline field under the Page Settings section along with other fields in the plugin settings were found to be vulnerable to stored XSS, which gets triggered when the Coming Soon page is displayed (both in preview mode and live). All WordPress websites using Coming Soon Page, Under Construction & Maintenance Mode by SeedProd version 5.1.1 and below are affected.
Mitigation:
Update the plugin to the latest version to mitigate this vulnerability.