Beta

Report

SeedProd Pro <= 6.18.13 is vulnerable to Remote Code Execution (RCE) vulnerability

Editor
Published
2024-12-10

The SeedProd Pro plugin for WordPress is vulnerable to Remote File Inclusion in all versions up to, and including, 6.18.13. This makes it possible for authenticated attackers, with Editor-level access and above, to include remote files on the server, resulting in code execution.

CVSS

Score:9.1

Severity:Critical

Version: 6.18.13

There is a patch available in v6.18.14 and we strongly recommend you update to this version as soon as possible.