Seedprod develops a focused suite of WordPress plugins and website-building tools, including RafflePress, its core Website Builder, Coming Soon pages, and notification-bar functionality, that serve site owners seeking landing-page and lead-capture capabilities. The vendor's vulnerability profile centers on web-application input-handling and authorization weaknesses—cross-site scripting, missing authorization checks, and cross-site request forgery—that are characteristic of client-side plugin code, and its disclosures tend to acquire public exploit code. Current severity, exploitation activity, and detailed exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Seedprod over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-15038MEDIUM The SeedProd coming-soon plugin before 5.1.1 for WordPress allows XSS. | Jun 24, 2020 | 5.4 | 27 | NO | YES |
CVE-2024-1072HIGH The Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode plugin for WordPress is vulnerable to unauthorized modification of data du | Feb 5, 2024 | 7.5 | 24 | NO | NO |
CVE-2024-4745MEDIUM Missing Authorization vulnerability in RafflePress Giveaways and Contests by RafflePress.This issue affects Giveaways and Contests by RafflePress: from n/a through 1.12.4. | Jun 10, 2024 | 6.3 | 19 | NO | NO |
CVE-2023-5049MEDIUM The Giveaways and Contests by RafflePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rafflepress' and 'rafflepress_gutenberg' shortcode in versions | Oct 30, 2023 | 5.4 | 18 | NO | NO |
CVE-2024-6887MEDIUM The Giveaways and Contests by RafflePress WordPress plugin before 1.12.16 does not sanitise and escape some of its Giveaways settings, which could allow high privilege users such | Sep 12, 2024 | 4.8 | 16 | NO | NO |
CVE-2024-37556MEDIUM Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SeedProd WordPress Notification Bar allows Stored XSS.This issue affect | Jul 21, 2024 | 4.8 | 16 | NO | NO |
CVE-2024-10107MEDIUM The Giveaways and Contests by RafflePress WordPress plugin before 1.12.17 does not sanitise and escape some of its settings, which could allow high privilege users such as admin t | May 15, 2025 | 4.8 | 15 | NO | NO |
CVE-2023-4975MEDIUM The Website Builder by SeedProd plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.15.13.1. This is due to missing or incorrect no | Oct 20, 2023 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Seedprod.
Media articles that mention a CVE ID that affects a product developed by Seedprod — matched by CVE ID, not by vendor name.