Curtain [curtain] <= 1.0.2 (unfixed + closed)
unknown
[en] The Curtain WordPress plugin through 1.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed
- Affected:
- up to 1.0.2
- Fix:
- No patched version reported
- Disclosed:
- May 23, 2022
CVE-2022-1558 on NVD →
Curtain <= 1.0.2 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Curtain WordPress plugin through 1.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed
- CVSS:
- 5.5
- Affected:
- up to 1.0.2
- Fix:
- No patched version reported
- Disclosed:
- Apr 27, 2022
CVE-2022-1558 on NVD →
Curtain [curtain] <= 1.0.2 (closed)
unknown
Stored Cross-Site Scripting (XSS) vulnerability was discovered by Hassan Khan Yusufzai (Splint3r7) in the WordPress Curtain plugin (versions <= 1.0.2).
- Affected:
- up to 1.0.2
- Fixed in:
- 1.0.2
- Disclosed:
- Apr 27, 2022
Curtain < 1.0.2 - Unauthenticated Maintenance Mode Enabled/Disable
medium
The Curtain plugin for WordPress is vulnerable to authorization bypass in versions up to, and including 1.0.1 due to insufficient capability and nonce checking on the admin_init function. This makes it possible for unauthenticated users to arbitrarily enable and disable maintenance mode on a vulnerable site.
- CVSS:
- 6.5
- Affected:
- up to 1.0.2
- Fixed in:
- 1.0.2
- Disclosed:
- Mar 30, 2022
Curtain [curtain] < 1.0.2 (closed)
unknown
Unauthenticated Maintenance Mode Switch vulnerability discovered by Hassan Khan Yusufzai (Splint3r7) in WordPress Curtain plugin (versions <= 1.0.1).
- Affected:
- up to 1.0.2
- Fixed in:
- 1.0.2
- Disclosed:
- Mar 30, 2022
Curtain [curtain] < 1.0.2 (closed)
unknown
The Curtain plugin for WordPress is vulnerable to authorization bypass in versions up to, and including 1.0.1 due to insufficient capability and nonce checking on the admin_init function. This makes it possible for unauthenticated users to arbitrarily enable and disable maintenance mode on a vulnerable site.
- Affected:
- up to 1.0.2
- Fixed in:
- 1.0.2
- Disclosed:
- Mar 30, 2022
Curtain [curtain] < 1.0.2 (closed)
unknown
The plugin does not have authorisation and CSRF checks in place when switching maintenance modes, which could allow unauthenticated attackers change maintenance modes
- Affected:
- up to 1.0.2
- Fixed in:
- 1.0.2
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database