Coming soon and Maintenance mode <= 3.7.3 - IP Address Spoofing via get_real_ip
medium
The Coming soon and Maintenance mode plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 3.7.3 due to the use of user-supplied HTTP headers as a primary method for IP retrieval. This makes it possible for attackers to bypass the coming soon mode page and visit the full site b...
- CVSS:
- 5.3
- Affected:
- up to 3.7.3
- Fixed in:
- 3.7.4
- Disclosed:
- Dec 1, 2023
CVE-2023-49741 on NVD →
Coming soon and Maintenance mode <= 3.6.6 - Missing Authorization to Arbitrary Email Send
medium
The Coming soon and Maintenance mode WordPress plugin before 3.6.8 does not have authorisation and CSRF checks in its coming_soon_send_mail AJAX action, allowing any authenticated users, with a role as low as subscriber to send arbitrary emails to all subscribed users.
- CVSS:
- 4.3
- Affected:
- up to 3.6.6
- Fixed in:
- 3.6.7
- Disclosed:
- Jan 24, 2022
CVE-2022-0164 on NVD →
Coming soon and Maintenance mode <= 3.6.7 - Cross-Site request Forgery to Arbitrary Email Send
high
The Coming soon and Maintenance mode WordPress plugin before 3.6.8 does not have CSRF check in its coming_soon_send_mail AJAX action, allowing attackers to make logged in admin to send arbitrary emails to all subscribed users via a CSRF attack
- CVSS:
- 8.8
- Affected:
- up to 3.6.8
- Fixed in:
- 3.6.8
- Disclosed:
- Jan 23, 2022
CVE-2022-0199 on NVD →
Coming soon and Maintenance mode <= 3.5.2 - Authenticated Stored Cross-Site Scripting
medium
The Coming soon and Maintenance mode WordPress plugin before 3.5.3 does not properly sanitize inputs submitted by authenticated users when setting adding or modifying coming soon or maintenance mode pages, leading to stored XSS.
- CVSS:
- 6.4
- Affected:
- up to 3.5.3
- Fixed in:
- 3.5.3
- Disclosed:
- Sep 13, 2021
CVE-2021-24577 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database