underConstruction [underconstruction] < 1.22
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noah Kagan underConstruction allows Stored XSS.This issue affects underConstruction: from n/a through 1.21.
- Affected:
- up to 1.22
- Fixed in:
- 1.22
- Disclosed:
- Mar 31, 2024
CVE-2024-30548 on NVD →
underConstruction <= 1.21 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The underConstruction plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.21 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject...
- CVSS:
- 4.4
- Affected:
- up to 1.21
- Fixed in:
- 1.22
- Disclosed:
- Mar 29, 2024
CVE-2024-30548 on NVD →
underConstruction [underconstruction] < 1.21
unknown
[en] The underConstruction WordPress plugin before 1.20 does not have CSRF check in place when deactivating the construction mode, which could allow attackers to make a logged in admin perform such action via a CSRF attack
- Affected:
- up to 1.21
- Fixed in:
- 1.21
- Disclosed:
- Jun 20, 2022
CVE-2022-1895 on NVD →
underConstruction [underconstruction] < 1.21
unknown
[en] The underConstruction WordPress plugin before 1.21 does not sanitise or escape the "Display a custom page using your own HTML" setting before outputting it, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiletred_html capability is disallowed.
- Affected:
- up to 1.21
- Fixed in:
- 1.21
- Disclosed:
- Jun 20, 2022
CVE-2022-1896 on NVD →
underConstruction <= 1.19 - Cross-Site Request Forgery to Construction Mode Disabled
high
The underConstruction WordPress plugin before 1.20 does not have CSRF check in place when deactivating the construction mode, which could allow attackers to make a logged in admin perform such action via a CSRF attack
- CVSS:
- 8.8
- Affected:
- up to 1.20
- Fixed in:
- 1.20
- Disclosed:
- May 26, 2022
CVE-2022-1895 on NVD →
underConstruction <= 1.20 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The underConstruction WordPress plugin before 1.21 does not sanitise or escape the "Display a custom page using your own HTML" setting before outputting it, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiletred_html capability is disallowed.
- CVSS:
- 5.5
- Affected:
- up to 1.21
- Fixed in:
- 1.21
- Disclosed:
- May 26, 2022
CVE-2022-1896 on NVD →
underConstruction [underconstruction] < 1.19
unknown
[en] The underConstruction plugin <= 1.18 for WordPress echoes out the raw value of `$GLOBALS['PHP_SELF']` in the ucOptions.php file. On certain configurations including Apache+modPHP, this makes it possible to use it to perform a reflected Cross-Site Scripting attack by injecting malicious code in the request path.
- Affected:
- up to 1.19
- Fixed in:
- 1.19
- Disclosed:
- Sep 1, 2021
CVE-2021-39320 on NVD →
underConstruction <= 1.18 - Reflected Cross-Site Scripting
medium
The underConstruction plugin <= 1.18 for WordPress echoes out the raw value of `$GLOBALS['PHP_SELF']` in the ucOptions.php file. On certain configurations including Apache+modPHP, this makes it possible to use it to perform a reflected Cross-Site Scripting attack by injecting malicious code in the request path.
- CVSS:
- 6.1
- Affected:
- up to 1.18
- Fixed in:
- 1.19
- Disclosed:
- Aug 31, 2021
CVE-2021-39320 on NVD →
underConstruction < 1.09 - Cross-Site Request Forgery
high
Cross-site request forgery (CSRF) vulnerability in the underConstruction plugin before 1.09 for WordPress allows remote attackers to hijack the authentication of administrators for requests that deactivate a plugin via unspecified vectors.
- CVSS:
- 8.8
- Affected:
- up to 1.09
- Fixed in:
- 1.09
- Disclosed:
- Aug 1, 2014
CVE-2013-2699 on NVD →
underConstruction [underconstruction] < 1.09
unknown
[en] Cross-site request forgery (CSRF) vulnerability in the underConstruction plugin before 1.09 for WordPress allows remote attackers to hijack the authentication of administrators for requests that deactivate a plugin via unspecified vectors.
- Affected:
- up to 1.09
- Fixed in:
- 1.09
- Disclosed:
- Apr 10, 2014
CVE-2013-2699 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database