Impact
The Website Builder by SeedProd plugin for WordPress contains a stored cross‑site scripting flaw in the seedprodnestedmenuwidget shortcode. The plugin fails to properly sanitize and escape user supplied attributes, allowing an attacker with contributor‑level or higher privileges to embed arbitrary JavaScript. The script is persisted in the database and will execute in the browsers of any user who views the affected page. The vulnerability is a classic injection weakness classified as CWE‑79.
Affected Systems
SeedProd Website Builder by SeedProd – Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode. Every WordPress installation running the plugin at version 6.20.2 or earlier is impacted. There are no additional constraints on the WordPress core or other plugins; the issue resides solely within the plugin code.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate severity. The EPSS score is < 1%, reflecting a very low but non‑zero probability of automated exploitation. The vulnerability is not included in the CISA KEV catalog, so it is not known to be widely exploited in the wild. An attacker must be authenticated with contributor or higher access in order to inject the malicious script. The attack path involves logging into widget that uses the seedprodnestedmenuwidget shortcode, inserting a malicious payload into an attribute field, saving the changes, and then any visitor to that page will execute the code.
OpenCVE Enrichment