CVE-2025-24540
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Jan 27, 2025
CWE ID 352
Summary
CVE-2025-24540 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the SeedProd Coming Soon Page, Under Construction & Maintenance Mode plugin. This issue permits unauthorized requests to be sent from one user to another, potentially leading to data manipulation or unintended actions. The vulnerability can be exploited on any version of the plugin from n/a to 6.18.9. Users are advised to update to the latest secure version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share