Coming Soon & Maintenance Mode Page <= 1.57 - Cross-Site Request Forgery
high
The Coming Soon & Maintenance Mode Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.57. This is due to confusing logic functions missing or having incorrect nonce validation. This makes it possible for unauthenticated attackers to gain and perform otherwise unaut...
- CVSS:
- 8.8
- Affected:
- up to 1.57
- Fixed in:
- 1.58
- Disclosed:
- Sep 16, 2020
CVE-2020-36707 on NVD →
Coming Soon & Maintenance Mode Page <= 1.57 - Cross-Site Request Forgery Bypass
medium
The Coming Soon & Maintenance Mode Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.57. This is due to missing or incorrect nonce validation on the save_meta_box() function. This makes it possible for unauthenticated attackers to save meta boxes via a forged requ...
- CVSS:
- 4.3
- Affected:
- up to 1.57
- Fixed in:
- 1.58
- Disclosed:
- Sep 16, 2020
CVE-2020-36752 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database