Impact
SeedProd Pro plugin versions older than 6.19.5 contain a contributor-controlled cross-site scripting vulnerability. When an untrusted contributor submits data that is stored and displayed by the plugin without proper sanitization, an attacker can inject malicious JavaScript. This potentially allows the attacker to steal session cookies, deface content, or perform other client-side malicious actions. The weakness is identified as CWE-79.
Affected Systems
WordPress sites using SeedProd LLC’s SeedProd Pro plugin before version 6.19.5 are affected. Any installation of the plugin that has not been upgraded to ≥ 6.19.5 is at risk, regardless of the WordPress core version or other plugins.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. The EPSS score is not available, so the exact likelihood of exploitation cannot be determined from this data, and the vulnerability is not listed in the CISA KEV catalog. Attackers would need to find a way to supply unescaped contributor data, likely through forms or admin interfaces. Once injected, the malicious script runs in the context of any user browsing a page that includes the vulnerable content.
OpenCVE Enrichment