plugin

Minimal Coming Soon Maintenance Mode Vulnerabilities

16 known security issues reported for the Minimal Coming Soon Maintenance Mode WordPress plugin. Most recent disclosed Jun 8, 2024.

2 high 4 medium 1 low

Running Minimal Coming Soon Maintenance Mode on your site? Check whether your installed version is affected.

Scan your site free

Minimal Coming Soon – Coming Soon Page [minimal-coming-soon-maintenance-mode] < 2.39

unknown

[en] The Minimal Coming Soon – Coming Soon Page plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the validate_ajax, deactivate_ajax, and save_ajax functions in all versions up to, and including, 2.38. This makes it possible for authenticated attackers, with Su...

Affected:
up to 2.39
Fixed in:
2.39
Disclosed:
Jun 8, 2024

CVE-2024-5087 on NVD →

Minimal Coming Soon – Coming Soon Page <= 2.38 - Missing Authorization to Limited Settings Change

medium

The Minimal Coming Soon – Coming Soon Page plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the validate_ajax, deactivate_ajax, and save_ajax functions in all versions up to, and including, 2.38. This makes it possible for authenticated attackers, with Subscri...

CVSS:
6.3
Affected:
up to 2.38
Fixed in:
2.39
Disclosed:
Jun 7, 2024

CVE-2024-5087 on NVD →

Minimal Coming Soon – Coming Soon Page <= 2.37 - Unauthenticated Maintenance Mode Bypass

low

The Minimal Coming Soon – Coming Soon Page plugin for WordPress is vulnerable to maintenance mode bypass and information disclosure in all versions up to, and including, 2.37. This is due to the plugin improperly validating the request path. This makes it possible for unauthenticated attackers to bypass maintenance mod...

CVSS:
3.7
Affected:
up to 2.37
Fixed in:
2.38
Disclosed:
Feb 5, 2024

CVE-2024-1075 on NVD →

Minimal Coming Soon – Coming Soon Page [minimal-coming-soon-maintenance-mode] < 2.38

unknown

[en] The Minimal Coming Soon – Coming Soon Page plugin for WordPress is vulnerable to maintenance mode bypass and information disclosure in all versions up to, and including, 2.37. This is due to the plugin improperly validating the request path. This makes it possible for unauthenticated attackers to bypass maintenanc...

Affected:
up to 2.38
Fixed in:
2.38
Disclosed:
Feb 5, 2024

CVE-2024-1075 on NVD →

Minimal Coming Soon – Coming Soon Page <= 2.33 - Authenticated (Administrator+) Cross-Site Scripting

medium

The Minimal Coming Soon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘custom_css’ and 'custom_html' parameters in versions up to, and including, 2.33 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level perm...

CVSS:
5.5
Affected:
up to 2.33
Fixed in:
2.35
Disclosed:
Nov 21, 2022

Minimal Coming Soon – Coming Soon Page [minimal-coming-soon-maintenance-mode] < 2.35

unknown

The Minimal Coming Soon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘custom_css’ and 'custom_html' parameters in versions up to, and including, 2.33 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level perm...

Affected:
up to 2.35
Fixed in:
2.35
Disclosed:
Nov 21, 2022

Minimal Coming Soon – Coming Soon Page <= 2.33 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Minimal Coming Soon – Coming Soon Page plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom_css value in versions up to, and including, 2.33 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative level permission...

CVSS:
5.5
Affected:
up to 2.34
Fixed in:
2.35
Disclosed:
Aug 5, 2022

Minimal Coming Soon – Coming Soon Page [minimal-coming-soon-maintenance-mode] < 2.35

unknown

The Minimal Coming Soon – Coming Soon Page plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom_css value in versions up to, and including, 2.33 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative level permission...

Affected:
up to 2.35
Fixed in:
2.35
Disclosed:
Aug 5, 2022

Minimal Coming Soon – Coming Soon Page [minimal-coming-soon-maintenance-mode] < 2.35

unknown

Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities discovered in WordPress Minimal Coming Soon – Coming Soon Page plugin (versions <= 2.33). Update the WordPress Minimal Coming Soon – Coming Soon Page plugin to the latest available version (at least 2.35).

Affected:
up to 2.35
Fixed in:
2.35
Disclosed:
May 23, 2022

Minimal Coming Soon – Coming Soon Page [minimal-coming-soon-maintenance-mode] < 2.17

unknown

[en] A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.15, allows authenticated users with basic access to export settings and change maintenance-mode themes.

Affected:
up to 2.17
Fixed in:
2.17
Disclosed:
Jan 9, 2020

CVE-2020-6166 on NVD →

Minimal Coming Soon – Coming Soon Page [minimal-coming-soon-maintenance-mode] < 2.15

unknown

[en] A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows a CSRF attack to enable maintenance mode, inject XSS, modify several important settings, or include remote files as a logo.

Affected:
up to 2.15
Fixed in:
2.15
Disclosed:
Jan 9, 2020

CVE-2020-6167 on NVD →

Minimal Coming Soon – Coming Soon Page [minimal-coming-soon-maintenance-mode] < 2.15

unknown

[en] A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows authenticated users with basic access to enable and disable maintenance-mode settings (impacting the availability and confidentiality of a vulnerable site, along with the integrity of the setting).

Affected:
up to 2.15
Fixed in:
2.15
Disclosed:
Jan 9, 2020

CVE-2020-6168 on NVD →

Minimal Coming Soon & Maintenance Mode <= 2.10 - Cross-Site Request Forgery to Stored Cross-Site Scripting and Setting Changes

high

A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows a CSRF attack to enable maintenance mode, inject XSS, modify several important settings, or include remote files as a logo.

CVSS:
8.8
Affected:
up to 2.10
Fixed in:
2.15
Disclosed:
Jan 8, 2020

CVE-2020-6167 on NVD →

Minimal Coming Soon & Maintenance Mode <= 2.16 - Missing Authorization to Export Settings/Theme Change

medium

A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.15, allows authenticated users with basic access to export settings and change maintenance-mode themes.

CVSS:
5.4
Affected:
up to 2.17
Fixed in:
2.17
Disclosed:
Jan 8, 2020

CVE-2020-6166 on NVD →

Minimal Coming Soon & Maintenance Mode <= 2.10 - Missing Authorization

high

A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows authenticated users with basic access to enable and disable maintenance-mode settings (impacting the availability and confidentiality of a vulnerable site, along with the integrity of the setting).

CVSS:
7.1
Affected:
up to 2.15
Fixed in:
2.15
Disclosed:
Dec 18, 2019

CVE-2020-6168 on NVD →

Minimal Coming Soon – Coming Soon Page [minimal-coming-soon-maintenance-mode] < 2.35

unknown

The plugin does not sanitize or escape some of its settings, allowing high privilege users such as admin to se Cross-Site Scripting payload in them, which will be triggered in the backend. A

Affected:
up to 2.35
Fixed in:
2.35

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database