Minimal Coming Soon – Coming Soon Page [minimal-coming-soon-maintenance-mode] < 2.39
unknown
[en] The Minimal Coming Soon – Coming Soon Page plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the validate_ajax, deactivate_ajax, and save_ajax functions in all versions up to, and including, 2.38. This makes it possible for authenticated attackers, with Su...
- Affected:
- up to 2.39
- Fixed in:
- 2.39
- Disclosed:
- Jun 8, 2024
CVE-2024-5087 on NVD →
Minimal Coming Soon – Coming Soon Page <= 2.38 - Missing Authorization to Limited Settings Change
medium
The Minimal Coming Soon – Coming Soon Page plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the validate_ajax, deactivate_ajax, and save_ajax functions in all versions up to, and including, 2.38. This makes it possible for authenticated attackers, with Subscri...
- CVSS:
- 6.3
- Affected:
- up to 2.38
- Fixed in:
- 2.39
- Disclosed:
- Jun 7, 2024
CVE-2024-5087 on NVD →
Minimal Coming Soon – Coming Soon Page <= 2.37 - Unauthenticated Maintenance Mode Bypass
low
The Minimal Coming Soon – Coming Soon Page plugin for WordPress is vulnerable to maintenance mode bypass and information disclosure in all versions up to, and including, 2.37. This is due to the plugin improperly validating the request path. This makes it possible for unauthenticated attackers to bypass maintenance mod...
- CVSS:
- 3.7
- Affected:
- up to 2.37
- Fixed in:
- 2.38
- Disclosed:
- Feb 5, 2024
CVE-2024-1075 on NVD →
Minimal Coming Soon – Coming Soon Page [minimal-coming-soon-maintenance-mode] < 2.38
unknown
[en] The Minimal Coming Soon – Coming Soon Page plugin for WordPress is vulnerable to maintenance mode bypass and information disclosure in all versions up to, and including, 2.37. This is due to the plugin improperly validating the request path. This makes it possible for unauthenticated attackers to bypass maintenanc...
- Affected:
- up to 2.38
- Fixed in:
- 2.38
- Disclosed:
- Feb 5, 2024
CVE-2024-1075 on NVD →
Minimal Coming Soon – Coming Soon Page <= 2.33 - Authenticated (Administrator+) Cross-Site Scripting
medium
The Minimal Coming Soon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘custom_css’ and 'custom_html' parameters in versions up to, and including, 2.33 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level perm...
- CVSS:
- 5.5
- Affected:
- up to 2.33
- Fixed in:
- 2.35
- Disclosed:
- Nov 21, 2022
Minimal Coming Soon – Coming Soon Page [minimal-coming-soon-maintenance-mode] < 2.35
unknown
The Minimal Coming Soon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘custom_css’ and 'custom_html' parameters in versions up to, and including, 2.33 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level perm...
- Affected:
- up to 2.35
- Fixed in:
- 2.35
- Disclosed:
- Nov 21, 2022
Minimal Coming Soon – Coming Soon Page <= 2.33 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Minimal Coming Soon – Coming Soon Page plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom_css value in versions up to, and including, 2.33 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative level permission...
- CVSS:
- 5.5
- Affected:
- up to 2.34
- Fixed in:
- 2.35
- Disclosed:
- Aug 5, 2022
Minimal Coming Soon – Coming Soon Page [minimal-coming-soon-maintenance-mode] < 2.35
unknown
The Minimal Coming Soon – Coming Soon Page plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom_css value in versions up to, and including, 2.33 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative level permission...
- Affected:
- up to 2.35
- Fixed in:
- 2.35
- Disclosed:
- Aug 5, 2022
Minimal Coming Soon – Coming Soon Page [minimal-coming-soon-maintenance-mode] < 2.35
unknown
Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities discovered in WordPress Minimal Coming Soon – Coming Soon Page plugin (versions <= 2.33).
Update the WordPress Minimal Coming Soon – Coming Soon Page plugin to the latest available version (at least 2.35).
- Affected:
- up to 2.35
- Fixed in:
- 2.35
- Disclosed:
- May 23, 2022
Minimal Coming Soon – Coming Soon Page [minimal-coming-soon-maintenance-mode] < 2.17
unknown
[en] A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.15, allows authenticated users with basic access to export settings and change maintenance-mode themes.
- Affected:
- up to 2.17
- Fixed in:
- 2.17
- Disclosed:
- Jan 9, 2020
CVE-2020-6166 on NVD →
Minimal Coming Soon – Coming Soon Page [minimal-coming-soon-maintenance-mode] < 2.15
unknown
[en] A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows a CSRF attack to enable maintenance mode, inject XSS, modify several important settings, or include remote files as a logo.
- Affected:
- up to 2.15
- Fixed in:
- 2.15
- Disclosed:
- Jan 9, 2020
CVE-2020-6167 on NVD →
Minimal Coming Soon – Coming Soon Page [minimal-coming-soon-maintenance-mode] < 2.15
unknown
[en] A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows authenticated users with basic access to enable and disable maintenance-mode settings (impacting the availability and confidentiality of a vulnerable site, along with the integrity of the setting).
- Affected:
- up to 2.15
- Fixed in:
- 2.15
- Disclosed:
- Jan 9, 2020
CVE-2020-6168 on NVD →
Minimal Coming Soon & Maintenance Mode <= 2.10 - Cross-Site Request Forgery to Stored Cross-Site Scripting and Setting Changes
high
A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows a CSRF attack to enable maintenance mode, inject XSS, modify several important settings, or include remote files as a logo.
- CVSS:
- 8.8
- Affected:
- up to 2.10
- Fixed in:
- 2.15
- Disclosed:
- Jan 8, 2020
CVE-2020-6167 on NVD →
Minimal Coming Soon & Maintenance Mode <= 2.16 - Missing Authorization to Export Settings/Theme Change
medium
A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.15, allows authenticated users with basic access to export settings and change maintenance-mode themes.
- CVSS:
- 5.4
- Affected:
- up to 2.17
- Fixed in:
- 2.17
- Disclosed:
- Jan 8, 2020
CVE-2020-6166 on NVD →
Minimal Coming Soon & Maintenance Mode <= 2.10 - Missing Authorization
high
A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows authenticated users with basic access to enable and disable maintenance-mode settings (impacting the availability and confidentiality of a vulnerable site, along with the integrity of the setting).
- CVSS:
- 7.1
- Affected:
- up to 2.15
- Fixed in:
- 2.15
- Disclosed:
- Dec 18, 2019
CVE-2020-6168 on NVD →
Minimal Coming Soon – Coming Soon Page [minimal-coming-soon-maintenance-mode] < 2.35
unknown
The plugin does not sanitize or escape some of its settings, allowing high privilege users such as admin to se Cross-Site Scripting payload in them, which will be triggered in the backend.
A
- Affected:
- up to 2.35
- Fixed in:
- 2.35
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database