← WordPress Vulnerabilities
WordPress security by component

Coming Soon Page, Under Construction & Maintenance Mode by SeedProd

Coming Soon Page, Under Construction & Maintenance Mode by SeedProd is a WordPress component with 10 published CVE records in this archive. The latest tracked vulnerability was published Apr 08, 2026; the highest CVE/CNA score is 6.1.

Plugin slug: coming-soon

CVE-2026-39464: Coming Soon Page, Under Construction & Maintenance Mode by SeedProd: Server-side request forgery

Coming Soon Page, Under Construction & Maintenance Mode by SeedProd is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests. The published affected range is <= 6.19.8.

PublishedApr 08, 2026
Known safe version6.19.9
Safe version
Apr 08, 2026 CVE-2026-39464
Coming Soon Page, Under Construction & Maintenance Mode by SeedProd: Server-side request forgery
Coming Soon Page, Under Construction & Maintenance Mode by SeedProd is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests. The published affected range is <= 6.19.8.
6.19.9
CVE5.5
NVDPending
Feb 19, 2026 CVE-2026-27368
Coming Soon Page, Under Construction & Maintenance Mode by SeedProd: A security weakness
Coming Soon Page, Under Construction & Maintenance Mode by SeedProd is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
May 09, 2025 CVE-2025-3949
Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode: A security weakness
Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Jan 27, 2025 CVE-2025-24540
Coming Soon Page, Under Construction & Maintenance Mode by SeedProd: Cross-site request forgery
Coming Soon Page, Under Construction & Maintenance Mode by SeedProd is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVDPending
Oct 06, 2024 CVE-2024-47299
Coming Soon Page, Under Construction & Maintenance Mode by SeedProd: Cross-site scripting
Coming Soon Page, Under Construction & Maintenance Mode by SeedProd is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVDPending
Apr 15, 2024 CVE-2024-32088
Coming Soon Page, Under Construction & Maintenance Mode by SeedProd: Cross-site request forgery
Coming Soon Page, Under Construction & Maintenance Mode by SeedProd is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVDPending
Oct 20, 2023 CVE-2023-4975
Website Builder by SeedProd: Cross-site request forgery
Website Builder by SeedProd is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD4.3
Aug 22, 2022 CVE-2022-1322
Coming Soon - Under Construction: Cross-site scripting
Coming Soon - Under Construction is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVD4.8
Apr 25, 2022 CVE-2021-46781
Coming Soon by Supsystic: Cross-site scripting
Coming Soon by Supsystic is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Jun 24, 2020 CVE-2020-15038
Coming Soon: Cross-site scripting
Coming Soon is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4