plugin

Curtain Vulnerabilities

7 known security issues reported for the Curtain WordPress plugin. Most recent disclosed May 23, 2022.

2 medium

Running Curtain on your site? Check whether your installed version is affected.

Scan your site free

Curtain [curtain] <= 1.0.2 (unfixed + closed)

unknown

[en] The Curtain WordPress plugin through 1.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed

Affected:
up to 1.0.2
Fix:
No patched version reported
Disclosed:
May 23, 2022

CVE-2022-1558 on NVD →

Curtain <= 1.0.2 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Curtain WordPress plugin through 1.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed

CVSS:
5.5
Affected:
up to 1.0.2
Fix:
No patched version reported
Disclosed:
Apr 27, 2022

CVE-2022-1558 on NVD →

Curtain [curtain] <= 1.0.2 (closed)

unknown

Stored Cross-Site Scripting (XSS) vulnerability was discovered by Hassan Khan Yusufzai (Splint3r7) in the WordPress Curtain plugin (versions <= 1.0.2).

Affected:
up to 1.0.2
Fixed in:
1.0.2
Disclosed:
Apr 27, 2022

Curtain < 1.0.2 - Unauthenticated Maintenance Mode Enabled/Disable

medium

The Curtain plugin for WordPress is vulnerable to authorization bypass in versions up to, and including 1.0.1 due to insufficient capability and nonce checking on the admin_init function. This makes it possible for unauthenticated users to arbitrarily enable and disable maintenance mode on a vulnerable site.

CVSS:
6.5
Affected:
up to 1.0.2
Fixed in:
1.0.2
Disclosed:
Mar 30, 2022

Curtain [curtain] < 1.0.2 (closed)

unknown

Unauthenticated Maintenance Mode Switch vulnerability discovered by Hassan Khan Yusufzai (Splint3r7) in WordPress Curtain plugin (versions <= 1.0.1).

Affected:
up to 1.0.2
Fixed in:
1.0.2
Disclosed:
Mar 30, 2022

Curtain [curtain] < 1.0.2 (closed)

unknown

The Curtain plugin for WordPress is vulnerable to authorization bypass in versions up to, and including 1.0.1 due to insufficient capability and nonce checking on the admin_init function. This makes it possible for unauthenticated users to arbitrarily enable and disable maintenance mode on a vulnerable site.

Affected:
up to 1.0.2
Fixed in:
1.0.2
Disclosed:
Mar 30, 2022

Curtain [curtain] < 1.0.2 (closed)

unknown

The plugin does not have authorisation and CSRF checks in place when switching maintenance modes, which could allow unauthenticated attackers change maintenance modes

Affected:
up to 1.0.2
Fixed in:
1.0.2

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database