plugin

Site Offline Vulnerabilities

8 known security issues reported for the Site Offline WordPress plugin. Most recent disclosed Aug 21, 2025.

1 high 3 medium

Running Site Offline on your site? Check whether your installed version is affected.

Scan your site free

Site Offline <= 1.5.7 - Missing Authorization

medium

The Site Offline Or Coming Soon Or Maintenance Mode plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.5.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorize...

CVSS:
4.3
Affected:
up to 1.5.7
Fix:
No patched version reported
Disclosed:
Aug 21, 2025

CVE-2025-48348 on NVD →

Site Offline Or Coming Soon Or Maintenance Mode [site-offline] < 1.5.7 (closed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chandra Shekhar Sahu Site Offline Or Coming Soon Or Maintenance Mode allows Stored XSS.This issue affects Site Offline Or Coming Soon Or Maintenance Mode: from n/a through 1.5.6.

Affected:
up to 1.5.7
Fixed in:
1.5.7
Disclosed:
Dec 15, 2023

CVE-2023-49190 on NVD →

Site Offline <= 1.5.6 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Site Offline Or Coming Soon Or Maintenance Mode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.5.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level pe...

CVSS:
4.4
Affected:
up to 1.5.6
Fixed in:
1.5.7
Disclosed:
Nov 29, 2023

CVE-2023-49190 on NVD →

Site Offline Or Coming Soon Or Maintenance Mode [site-offline] < 1.5.3 (closed)

unknown

[en] The Site Offline Or Coming Soon Or Maintenance Mode WordPress plugin before 1.5.3 prevents users from accessing a website but does not do so if the URL contained certain keywords. Adding those keywords to the URL's query string would bypass the plugin's main feature.

Affected:
up to 1.5.3
Fixed in:
1.5.3
Disclosed:
Sep 19, 2022

CVE-2022-1580 on NVD →

Site Offline <= 1.4.9 - Maintenance Mode Bypass

medium

The Site Offline plugin for WordPress is vulnerable to Maintenance Mode Bypass in versions up to, and including, 1.4.9. The presence of certain keywords in the URL allowed users to visit a site placed in maintenance mode thus bypassing the plugin's provided feature.

CVSS:
5.3
Affected:
up to 1.4.9
Fixed in:
1.5.3
Disclosed:
Aug 29, 2022

CVE-2022-1580 on NVD →

Site Offline Or Coming Soon Or Maintenance Mode [site-offline] < 1.4.4 (closed)

unknown

[en] The site-offline plugin before 1.4.4 for WordPress lacks certain wp_create_nonce and wp_verify_nonce calls, aka CSRF.

Affected:
up to 1.4.4
Fixed in:
1.4.4
Disclosed:
Dec 29, 2020

CVE-2020-35773 on NVD →

Site Offline Or Coming Soon Or Maintenance Mode <= 1.4.2 - Cross-Site Request Forgery and Cross-Site Scripting

high

The Site Offline Or Coming Soon Or Maintenance Mode plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.2. This is due to missing or incorrect nonce validation on an unknown function. This makes it possible for unauthenticated attackers to perform an unknown action gra...

CVSS:
8.2
Affected:
up to 1.4.2
Fixed in:
1.4.4
Disclosed:
Dec 23, 2020

CVE-2020-35773 on NVD →

Site Offline Or Coming Soon Or Maintenance Mode [site-offline] <= 1.5.7 (unfixed + closed)

unknown
Affected:
up to 1.5.7
Fix:
No patched version reported

CVE-2025-48348 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database