Site Offline <= 1.5.7 - Missing Authorization
medium
The Site Offline Or Coming Soon Or Maintenance Mode plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.5.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorize...
- CVSS:
- 4.3
- Affected:
- up to 1.5.7
- Fix:
- No patched version reported
- Disclosed:
- Aug 21, 2025
CVE-2025-48348 on NVD →
Site Offline Or Coming Soon Or Maintenance Mode [site-offline] < 1.5.7 (closed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chandra Shekhar Sahu Site Offline Or Coming Soon Or Maintenance Mode allows Stored XSS.This issue affects Site Offline Or Coming Soon Or Maintenance Mode: from n/a through 1.5.6.
- Affected:
- up to 1.5.7
- Fixed in:
- 1.5.7
- Disclosed:
- Dec 15, 2023
CVE-2023-49190 on NVD →
Site Offline <= 1.5.6 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Site Offline Or Coming Soon Or Maintenance Mode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.5.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level pe...
- CVSS:
- 4.4
- Affected:
- up to 1.5.6
- Fixed in:
- 1.5.7
- Disclosed:
- Nov 29, 2023
CVE-2023-49190 on NVD →
Site Offline Or Coming Soon Or Maintenance Mode [site-offline] < 1.5.3 (closed)
unknown
[en] The Site Offline Or Coming Soon Or Maintenance Mode WordPress plugin before 1.5.3 prevents users from accessing a website but does not do so if the URL contained certain keywords. Adding those keywords to the URL's query string would bypass the plugin's main feature.
- Affected:
- up to 1.5.3
- Fixed in:
- 1.5.3
- Disclosed:
- Sep 19, 2022
CVE-2022-1580 on NVD →
Site Offline <= 1.4.9 - Maintenance Mode Bypass
medium
The Site Offline plugin for WordPress is vulnerable to Maintenance Mode Bypass in versions up to, and including, 1.4.9. The presence of certain keywords in the URL allowed users to visit a site placed in maintenance mode thus bypassing the plugin's provided feature.
- CVSS:
- 5.3
- Affected:
- up to 1.4.9
- Fixed in:
- 1.5.3
- Disclosed:
- Aug 29, 2022
CVE-2022-1580 on NVD →
Site Offline Or Coming Soon Or Maintenance Mode [site-offline] < 1.4.4 (closed)
unknown
[en] The site-offline plugin before 1.4.4 for WordPress lacks certain wp_create_nonce and wp_verify_nonce calls, aka CSRF.
- Affected:
- up to 1.4.4
- Fixed in:
- 1.4.4
- Disclosed:
- Dec 29, 2020
CVE-2020-35773 on NVD →
Site Offline Or Coming Soon Or Maintenance Mode <= 1.4.2 - Cross-Site Request Forgery and Cross-Site Scripting
high
The Site Offline Or Coming Soon Or Maintenance Mode plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.2. This is due to missing or incorrect nonce validation on an unknown function. This makes it possible for unauthenticated attackers to perform an unknown action gra...
- CVSS:
- 8.2
- Affected:
- up to 1.4.2
- Fixed in:
- 1.4.4
- Disclosed:
- Dec 23, 2020
CVE-2020-35773 on NVD →
Site Offline Or Coming Soon Or Maintenance Mode [site-offline] <= 1.5.7 (unfixed + closed)
unknown
- Affected:
- up to 1.5.7
- Fix:
- No patched version reported
CVE-2025-48348 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database