Impact
A Cross‑Site Request Forgery flaw in the SeedProd Coming Soon Page, Under Construction & Maintenance Mode plugin allows an attacker to trick a legitimate user into submitting a request that performs an operation the user is permitted to perform. This may expose the site to unintended administrative changes or content modifications, depending on the privileges the user holds.
Affected Systems
SeedProd "Coming Soon Page, Under Construction & Maintenance Mode" plugin, versions n/a through 6.18.9 are vulnerable. Any WordPress installation using those versions is affected.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, and the EPSS score is below 1%, suggesting a low likelihood of widespread exploitation. The vulnerability is not currently listed in CISA's KEV catalog. Likely exploitation requires a logged‑in user and a crafted CSRF request delivered via a nearby web page or malicious link. Exploitability is limited by the need for user interaction and valid authentication tokens.
OpenCVE Enrichment
EUVD