plugin

Underconstruction Vulnerabilities

10 known security issues reported for the Underconstruction WordPress plugin. Most recent disclosed Mar 31, 2024.

2 high 3 medium

Running Underconstruction on your site? Check whether your installed version is affected.

Scan your site free

underConstruction [underconstruction] < 1.22

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noah Kagan underConstruction allows Stored XSS.This issue affects underConstruction: from n/a through 1.21.

Affected:
up to 1.22
Fixed in:
1.22
Disclosed:
Mar 31, 2024

CVE-2024-30548 on NVD →

underConstruction <= 1.21 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The underConstruction plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.21 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject...

CVSS:
4.4
Affected:
up to 1.21
Fixed in:
1.22
Disclosed:
Mar 29, 2024

CVE-2024-30548 on NVD →

underConstruction [underconstruction] < 1.21

unknown

[en] The underConstruction WordPress plugin before 1.20 does not have CSRF check in place when deactivating the construction mode, which could allow attackers to make a logged in admin perform such action via a CSRF attack

Affected:
up to 1.21
Fixed in:
1.21
Disclosed:
Jun 20, 2022

CVE-2022-1895 on NVD →

underConstruction [underconstruction] < 1.21

unknown

[en] The underConstruction WordPress plugin before 1.21 does not sanitise or escape the "Display a custom page using your own HTML" setting before outputting it, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiletred_html capability is disallowed.

Affected:
up to 1.21
Fixed in:
1.21
Disclosed:
Jun 20, 2022

CVE-2022-1896 on NVD →

underConstruction <= 1.19 - Cross-Site Request Forgery to Construction Mode Disabled

high

The underConstruction WordPress plugin before 1.20 does not have CSRF check in place when deactivating the construction mode, which could allow attackers to make a logged in admin perform such action via a CSRF attack

CVSS:
8.8
Affected:
up to 1.20
Fixed in:
1.20
Disclosed:
May 26, 2022

CVE-2022-1895 on NVD →

underConstruction <= 1.20 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The underConstruction WordPress plugin before 1.21 does not sanitise or escape the "Display a custom page using your own HTML" setting before outputting it, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiletred_html capability is disallowed.

CVSS:
5.5
Affected:
up to 1.21
Fixed in:
1.21
Disclosed:
May 26, 2022

CVE-2022-1896 on NVD →

underConstruction [underconstruction] < 1.19

unknown

[en] The underConstruction plugin <= 1.18 for WordPress echoes out the raw value of `$GLOBALS['PHP_SELF']` in the ucOptions.php file. On certain configurations including Apache+modPHP, this makes it possible to use it to perform a reflected Cross-Site Scripting attack by injecting malicious code in the request path.

Affected:
up to 1.19
Fixed in:
1.19
Disclosed:
Sep 1, 2021

CVE-2021-39320 on NVD →

underConstruction <= 1.18 - Reflected Cross-Site Scripting

medium

The underConstruction plugin <= 1.18 for WordPress echoes out the raw value of `$GLOBALS['PHP_SELF']` in the ucOptions.php file. On certain configurations including Apache+modPHP, this makes it possible to use it to perform a reflected Cross-Site Scripting attack by injecting malicious code in the request path.

CVSS:
6.1
Affected:
up to 1.18
Fixed in:
1.19
Disclosed:
Aug 31, 2021

CVE-2021-39320 on NVD →

underConstruction < 1.09 - Cross-Site Request Forgery

high

Cross-site request forgery (CSRF) vulnerability in the underConstruction plugin before 1.09 for WordPress allows remote attackers to hijack the authentication of administrators for requests that deactivate a plugin via unspecified vectors.

CVSS:
8.8
Affected:
up to 1.09
Fixed in:
1.09
Disclosed:
Aug 1, 2014

CVE-2013-2699 on NVD →

underConstruction [underconstruction] < 1.09

unknown

[en] Cross-site request forgery (CSRF) vulnerability in the underConstruction plugin before 1.09 for WordPress allows remote attackers to hijack the authentication of administrators for requests that deactivate a plugin via unspecified vectors.

Affected:
up to 1.09
Fixed in:
1.09
Disclosed:
Apr 10, 2014

CVE-2013-2699 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database