plugin

Under Construction Page Vulnerabilities

10 known security issues reported for the Under Construction Page WordPress plugin. Most recent disclosed Jul 10, 2026.

4 medium

Running Under Construction Page on your site? Check whether your installed version is affected.

Scan your site free

UnderConstructionPage PRO <= 5.76 - Authenticated (Subscriber+) Arbitrary File Read via template_thumbnail Parameter

medium

The UnderConstructionPage PRO plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 5.76. This is due to the plugin accepting arbitrary local file paths in the template_thumbnail parameter and copying their contents into a publicly accessible uploads file. This makes it possibl...

CVSS:
6.5
Affected:
up to 5.76
Fixed in:
5.81
Disclosed:
Jul 10, 2026

CVE-2026-11426 on NVD →

Under Construction [under-construction-page] < 3.97

unknown

[en] The Under Construction plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.96. This is due to missing or incorrect nonce validation on the install_weglot function called via the admin_action_install_weglot action. This makes it possible for unauthenticated attackers...

Affected:
up to 3.97
Fixed in:
3.97
Disclosed:
Jun 9, 2023

CVE-2023-0832 on NVD →

Under Construction [under-construction-page] < 3.97

unknown

[en] The Under Construction plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.96. This is due to missing or incorrect nonce validation on the dismiss_notice function called via the admin_action_ucp_dismiss_notice action. This makes it possible for unauthenticated attac...

Affected:
up to 3.97
Fixed in:
3.97
Disclosed:
Jun 9, 2023

CVE-2023-0831 on NVD →

Under Construction <= 3.96 - Cross-Site Request Forgery via admin_action_ucp_dismiss_notice

medium

The Under Construction plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.96. This is due to missing or incorrect nonce validation on the dismiss_notice function called via the admin_action_ucp_dismiss_notice action. This makes it possible for unauthenticated attackers...

CVSS:
4.3
Affected:
up to 3.96
Fixed in:
3.97
Disclosed:
Feb 10, 2023

CVE-2023-0831 on NVD →

Under Construction <= 3.96 - Cross-Site Request Forgery via admin_action_install_weglot

medium

The Under Construction plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.96. This is due to missing or incorrect nonce validation on the install_weglot function called via the admin_action_install_weglot action. This makes it possible for unauthenticated attackers to p...

CVSS:
4.3
Affected:
up to 3.96
Fixed in:
3.97
Disclosed:
Feb 10, 2023

CVE-2023-0832 on NVD →

Under Construction [under-construction-page] < 3.97

unknown

Update the WordPress Under Construction plugin to the latest available version (at least 3.97). An unknown person discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Under Construction Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted a...

Affected:
up to 3.97
Fixed in:
3.97
Disclosed:
Feb 10, 2023

Under Construction <= 3.85 - Authenticated Stored Cross-Site Scripting

medium

The Under Construction plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 3.85, that make it possible for attackers with administrative privileges to inject arbitrary web scripts via the social and connect icon fields.

CVSS:
5.5
Affected:
up to 3.85
Fixed in:
3.86
Disclosed:
Jan 20, 2021

Under Construction [under-construction-page] < 3.86

unknown

Authenticated Stored Cross-Site Scripting (XSS) vulnerability found by Julien (atmon3r) in WordPress Under Construction plugin (versions <= 3.85).

Affected:
up to 3.86
Fixed in:
3.86
Disclosed:
Jan 20, 2021

Under Construction [under-construction-page] < 3.86

unknown

The Under Construction plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 3.85, that make it possible for attackers with administrative privileges to inject arbitrary web scripts via the social and connect icon fields.

Affected:
up to 3.86
Fixed in:
3.86
Disclosed:
Jan 20, 2021

Under Construction [under-construction-page] < 3.86

unknown

The Underconstruction plugin admin configuration is vulnerable to stored XSS issues which will be triggered in the main page of the site, even when the unfiltered_html is disabled. Edit (WPScanTeam) A fix was attempted in v3.80, but was insufficient. In the meantime, more fields were found to be affected and the ve...

Affected:
up to 3.86
Fixed in:
3.86

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database