plugin

Wp Maintenance Mode Site Under Construction Vulnerabilities

17 known security issues reported for the Wp Maintenance Mode Site Under Construction WordPress plugin. Most recent disclosed Jun 6, 2025.

4 high 1 medium

Running Wp Maintenance Mode Site Under Construction on your site? Check whether your installed version is affected.

Scan your site free

WP Maintenance Mode &amp; Site Under Construction [wp-maintenance-mode-site-under-construction] < 4.4

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in wp-buy WP Maintenance Mode & Site Under Construction allows Cross Site Request Forgery. This issue affects WP Maintenance Mode & Site Under Construction: from n/a through 4.3.

Affected:
up to 4.4
Fixed in:
4.4
Disclosed:
Jun 6, 2025

CVE-2025-49284 on NVD →

WP Maintenance Mode & Site Under Construction <= 4.3 - Cross-Site Request Forgery

medium

The WP Maintenance Mode & Site Under Construction plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.3. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action granted...

CVSS:
4.3
Affected:
up to 4.3
Fixed in:
4.4
Disclosed:
Jun 5, 2025

CVE-2025-49284 on NVD →

WP Maintenance Mode &amp; Site Under Construction [wp-maintenance-mode-site-under-construction] < 1.8.2

unknown

[en] Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Login as User or Customer (User Switching) WordPress plugin before 1.8, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps...

Affected:
up to 1.8.2
Fixed in:
1.8.2
Disclosed:
May 14, 2021

CVE-2021-24195 on NVD →

WP Maintenance Mode &amp; Site Under Construction [wp-maintenance-mode-site-under-construction] < 1.8.2

unknown

[en] Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WooCommerce Conditional Marketing Mailer WordPress plugin before 1.5.2, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps...

Affected:
up to 1.8.2
Fixed in:
1.8.2
Disclosed:
May 14, 2021

CVE-2021-24190 on NVD →

WP Maintenance Mode &amp; Site Under Construction [wp-maintenance-mode-site-under-construction] < 1.8.2

unknown

[en] Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Captchinoo, Google recaptcha for admin login page WordPress plugin before 2.4, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which...

Affected:
up to 1.8.2
Fixed in:
1.8.2
Disclosed:
May 14, 2021

CVE-2021-24189 on NVD →

WP Maintenance Mode &amp; Site Under Construction [wp-maintenance-mode-site-under-construction] < 1.8.2

unknown

[en] Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WP Content Copy Protection & No Right Click WordPress plugin before 3.1.5, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which hel...

Affected:
up to 1.8.2
Fixed in:
1.8.2
Disclosed:
May 14, 2021

CVE-2021-24188 on NVD →

WP Maintenance Mode &amp; Site Under Construction [wp-maintenance-mode-site-under-construction] < 1.8.2

unknown

[en] Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Login Protection - Limit Failed Login Attempts WordPress plugin before 2.9, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which he...

Affected:
up to 1.8.2
Fixed in:
1.8.2
Disclosed:
May 14, 2021

CVE-2021-24194 on NVD →

WP Maintenance Mode &amp; Site Under Construction [wp-maintenance-mode-site-under-construction] < 1.8.2

unknown

[en] Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Tree Sitemap WordPress plugin before 2.9, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attackers install vulnerable p...

Affected:
up to 1.8.2
Fixed in:
1.8.2
Disclosed:
May 14, 2021

CVE-2021-24192 on NVD →

WP Maintenance Mode &amp; Site Under Construction [wp-maintenance-mode-site-under-construction] < 1.8.2

unknown

[en] Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Visitor Traffic Real Time Statistics WordPress plugin before 2.12, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attac...

Affected:
up to 1.8.2
Fixed in:
1.8.2
Disclosed:
May 14, 2021

CVE-2021-24193 on NVD →

WP Maintenance Mode &amp; Site Under Construction [wp-maintenance-mode-site-under-construction] < 1.8.2

unknown

[en] Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WP Maintenance Mode & Site Under Construction WordPress plugin before 1.8.2, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which h...

Affected:
up to 1.8.2
Fixed in:
1.8.2
Disclosed:
May 14, 2021

CVE-2021-24191 on NVD →

Conditional Marketing Mailer for WooCommerce <= 1.5.2 - Cross-Site Request Forgery to Arbitrary Plugin Installation/Activation

high

The Conditional Marketing Mailer for WooCommerce Plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.2. This is due to missing or incorrect nonce validation on the 'cp_plugins_do_button_job_later_callback' AJAX action. This makes it possible for unauthenticated attacke...

CVSS:
8.8
Affected:
up to 1.5.2
Fixed in:
1.6
Disclosed:
Apr 22, 2021

WP Maintenance Mode & Site Under Construction <= 1.8.2 - Cross-Site Request Forgery to Arbitrary Plugin Installation/Activation

high

WP Maintenance Mode & Site Under Construction Plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.2. This is due to missing or incorrect nonce validation on the 'cp_plugins_do_button_job_later_callback' AJAX action. This makes it possible for unauthenticated attackers...

CVSS:
8.8
Affected:
up to 1.8.2
Fixed in:
1.9
Disclosed:
Apr 22, 2021

WP Maintenance Mode & Site Under Construction < 1.8.2 - Missing Authorization to Arbitrary Plugin Installation/Activation

high

Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WP Maintenance Mode & Site Under Construction WordPress plugin before 1.8.2, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps...

CVSS:
8.8
Affected:
up to 1.8.2
Fixed in:
1.8.2
Disclosed:
Apr 22, 2021

CVE-2021-24191 on NVD →

WooCommerce Conditional Marketing Mailer <= 1.5.1 - Improper Authorization

high

Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WooCommerce Conditional Marketing Mailer WordPress plugin before 1.5.2, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from the blog, which helps attack...

CVSS:
8.8
Affected:
up to 1.5.2
Fixed in:
1.5.2
Disclosed:
Apr 22, 2021

CVE-2021-24190 on NVD →

WP Maintenance Mode &amp; Site Under Construction [wp-maintenance-mode-site-under-construction] < 1.6

unknown

The Conditional Marketing Mailer for WooCommerce Plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.2. This is due to missing or incorrect nonce validation on the 'cp_plugins_do_button_job_later_callback' AJAX action. This makes it possible for unauthenticated attacke...

Affected:
up to 1.6
Fixed in:
1.6
Disclosed:
Apr 22, 2021

WP Maintenance Mode &amp; Site Under Construction [wp-maintenance-mode-site-under-construction] < 1.9

unknown

WP Maintenance Mode & Site Under Construction Plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.2. This is due to missing or incorrect nonce validation on the 'cp_plugins_do_button_job_later_callback' AJAX action. This makes it possible for unauthenticated attackers...

Affected:
up to 1.9
Fixed in:
1.9
Disclosed:
Apr 22, 2021

WP Maintenance Mode &amp; Site Under Construction [wp-maintenance-mode-site-under-construction] < 1.9

unknown

The &quot;cp_plugins_do_button_job_later_callback&quot; AJAX action, from multiple plugins of the WP-Buy vendor, was lacking CSRF check, allowing attackers to make a logged in administrator install and active arbitrary plugins (including specific version) from the WordPress repository which could lead to more critical...

Affected:
up to 1.9
Fixed in:
1.9

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database