plugin

Wp Maintenance Mode Vulnerabilities

13 known security issues reported for the Wp Maintenance Mode WordPress plugin. Most recent disclosed Feb 1, 2024.

1 critical 1 high 5 medium

Running Wp Maintenance Mode on your site? Check whether your installed version is affected.

Scan your site free

ThemeIsle SDK <= Various Versions - Missing Authorization

medium

Multiple plugins and/or themes for WordPress with the ThemeIsle SDK are vulnerable to unauthorized modification of data due to a missing capability check on the register_reference() function in various versions. This makes it possible for unauthenticated attackers to update options values that allow ThemeIsle to track...

CVSS:
5.3
Affected:
up to 2.6.9
Fixed in:
2.6.10
Disclosed:
Feb 1, 2024

CVE-2024-1047 on NVD →

LightStart &#8211; Maintenance Mode, Coming Soon and Landing Page Builder [wp-maintenance-mode] < 2.6.9

unknown

[en] The LightStart – Maintenance Mode, Coming Soon and Landing Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the insert_template function in all versions up to, and including, 2.6.8. This makes it possible for authenticated attackers, with sub...

Affected:
up to 2.6.9
Fixed in:
2.6.9
Disclosed:
Jan 11, 2024

CVE-2023-7019 on NVD →

LightStart – Maintenance Mode, Coming Soon and Landing Page Builder <= 2.6.8 - Missing Authorization

medium

The LightStart – Maintenance Mode, Coming Soon and Landing Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the insert_template function in all versions up to, and including, 2.6.8. This makes it possible for authenticated attackers, with subscrib...

CVSS:
4.3
Affected:
up to 2.6.8
Fixed in:
2.6.9
Disclosed:
Jan 5, 2024

CVE-2023-7019 on NVD →

LightStart &#8211; Maintenance Mode, Coming Soon and Landing Page Builder [wp-maintenance-mode] < 2.4.5

unknown

[en] The WP Maintenance Mode & Coming Soon WordPress plugin before 2.4.5 is lacking CSRF when emptying the subscribed users list, which could allow attackers to make a logged in admin perform such action via a CSRF attack

Affected:
up to 2.4.5
Fixed in:
2.4.5
Disclosed:
Jul 11, 2022

CVE-2022-1576 on NVD →

WP Maintenance Mode & Coming Soon <= 2.4.4 - Cross-Site Request Forgery

high

The WP Maintenance Mode & Coming Soon plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.4. This is due to missing nonce validation on the reset_plugin_settings, subscribers_empty_list, dismiss_notices, subscribers_export, add_subscriber, & send_contact functions. Thi...

CVSS:
8.8
Affected:
up to 2.4.4
Fixed in:
2.4.5
Disclosed:
Jun 20, 2022

CVE-2022-1576 on NVD →

WP Maintenance Mode <= 2.0.6 - Remote Code Execution

critical

The WP Maintenance Mode plugin before 2.0.7 for WordPress allows remote authenticated "site administrator" users to execute arbitrary PHP code throughout a multisite network.

CVSS:
9.1
Affected:
up to 2.0.7
Fixed in:
2.0.7
Disclosed:
Dec 14, 2018

CVE-2018-20156 on NVD →

LightStart &#8211; Maintenance Mode, Coming Soon and Landing Page Builder [wp-maintenance-mode] < 2.0.7

unknown

[en] The WP Maintenance Mode plugin before 2.0.7 for WordPress allows remote authenticated "site administrator" users to execute arbitrary PHP code throughout a multisite network.

Affected:
up to 2.0.7
Fixed in:
2.0.7
Disclosed:
Dec 14, 2018

CVE-2018-20156 on NVD →

LightStart &#8211; Maintenance Mode, Coming Soon and Landing Page Builder [wp-maintenance-mode] < 2.0.7

unknown

[en] The WP Maintenance Mode plugin before 2.0.7 for WordPress allows remote authenticated subscriber users to bypass intended access restrictions on changes to plugin settings.

Affected:
up to 2.0.7
Fixed in:
2.0.7
Disclosed:
Dec 14, 2018

CVE-2018-20155 on NVD →

LightStart &#8211; Maintenance Mode, Coming Soon and Landing Page Builder [wp-maintenance-mode] < 2.0.7

unknown

[en] The WP Maintenance Mode plugin before 2.0.7 for WordPress allows remote authenticated users to discover all subscriber e-mail addresses.

Affected:
up to 2.0.7
Fixed in:
2.0.7
Disclosed:
Dec 14, 2018

CVE-2018-20154 on NVD →

WP Maintenance Mode <= 2.0.6 - Missing Authorization

medium

The WP Maintenance Mode plugin before 2.0.7 for WordPress allows remote authenticated subscriber users to bypass intended access restrictions on changes to plugin settings.

CVSS:
5.4
Affected:
up to 2.0.7
Fixed in:
2.0.7
Disclosed:
Jul 6, 2016

CVE-2018-20155 on NVD →

WP Maintenance Mode <= 2.0.6 - Authenticated Information Disclosure

medium

The WP Maintenance Mode plugin before 2.0.7 for WordPress allows remote authenticated users to discover all subscriber e-mail addresses.

CVSS:
4.3
Affected:
up to 2.0.7
Fixed in:
2.0.7
Disclosed:
Jul 6, 2016

CVE-2018-20154 on NVD →

LightStart &#8211; Maintenance Mode, Coming Soon and Landing Page Builder [wp-maintenance-mode] < 1.8.8

unknown

[en] Cross-site request forgery (CSRF) vulnerability in the WP Maintenance Mode plugin before 1.8.8 for WordPress allows remote attackers to hijack the authentication of arbitrary users for requests that modify this plugin's settings.

Affected:
up to 1.8.8
Fixed in:
1.8.8
Disclosed:
Jun 21, 2013

CVE-2013-3250 on NVD →

WP Maintenance Mode <= 1.8.7 - Missing Authorization Checks & Cross-Site Request Forgery

medium

Cross-site request forgery (CSRF) vulnerability in the WP Maintenance Mode plugin before 1.8.8 for WordPress allows remote attackers to hijack the authentication of arbitrary users for requests that modify this plugin's settings.

CVSS:
5.4
Affected:
up to 1.8.8
Fixed in:
1.8.8
Disclosed:
Jun 5, 2013

CVE-2013-3250 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database