WP Maintenance Mode & Site Under Construction [wp-maintenance-mode-site-under-construction] < 4.4
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in wp-buy WP Maintenance Mode & Site Under Construction allows Cross Site Request Forgery. This issue affects WP Maintenance Mode & Site Under Construction: from n/a through 4.3.
- Affected:
- up to 4.4
- Fixed in:
- 4.4
- Disclosed:
- Jun 6, 2025
CVE-2025-49284 on NVD →
WP Maintenance Mode & Site Under Construction <= 4.3 - Cross-Site Request Forgery
medium
The WP Maintenance Mode & Site Under Construction plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.3. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action granted...
- CVSS:
- 4.3
- Affected:
- up to 4.3
- Fixed in:
- 4.4
- Disclosed:
- Jun 5, 2025
CVE-2025-49284 on NVD →
WP Maintenance Mode & Site Under Construction [wp-maintenance-mode-site-under-construction] < 1.8.2
unknown
[en] Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Login as User or Customer (User Switching) WordPress plugin before 1.8, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps...
- Affected:
- up to 1.8.2
- Fixed in:
- 1.8.2
- Disclosed:
- May 14, 2021
CVE-2021-24195 on NVD →
WP Maintenance Mode & Site Under Construction [wp-maintenance-mode-site-under-construction] < 1.8.2
unknown
[en] Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WooCommerce Conditional Marketing Mailer WordPress plugin before 1.5.2, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps...
- Affected:
- up to 1.8.2
- Fixed in:
- 1.8.2
- Disclosed:
- May 14, 2021
CVE-2021-24190 on NVD →
WP Maintenance Mode & Site Under Construction [wp-maintenance-mode-site-under-construction] < 1.8.2
unknown
[en] Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Captchinoo, Google recaptcha for admin login page WordPress plugin before 2.4, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which...
- Affected:
- up to 1.8.2
- Fixed in:
- 1.8.2
- Disclosed:
- May 14, 2021
CVE-2021-24189 on NVD →
WP Maintenance Mode & Site Under Construction [wp-maintenance-mode-site-under-construction] < 1.8.2
unknown
[en] Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WP Content Copy Protection & No Right Click WordPress plugin before 3.1.5, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which hel...
- Affected:
- up to 1.8.2
- Fixed in:
- 1.8.2
- Disclosed:
- May 14, 2021
CVE-2021-24188 on NVD →
WP Maintenance Mode & Site Under Construction [wp-maintenance-mode-site-under-construction] < 1.8.2
unknown
[en] Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Login Protection - Limit Failed Login Attempts WordPress plugin before 2.9, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which he...
- Affected:
- up to 1.8.2
- Fixed in:
- 1.8.2
- Disclosed:
- May 14, 2021
CVE-2021-24194 on NVD →
WP Maintenance Mode & Site Under Construction [wp-maintenance-mode-site-under-construction] < 1.8.2
unknown
[en] Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Tree Sitemap WordPress plugin before 2.9, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attackers install vulnerable p...
- Affected:
- up to 1.8.2
- Fixed in:
- 1.8.2
- Disclosed:
- May 14, 2021
CVE-2021-24192 on NVD →
WP Maintenance Mode & Site Under Construction [wp-maintenance-mode-site-under-construction] < 1.8.2
unknown
[en] Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Visitor Traffic Real Time Statistics WordPress plugin before 2.12, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attac...
- Affected:
- up to 1.8.2
- Fixed in:
- 1.8.2
- Disclosed:
- May 14, 2021
CVE-2021-24193 on NVD →
WP Maintenance Mode & Site Under Construction [wp-maintenance-mode-site-under-construction] < 1.8.2
unknown
[en] Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WP Maintenance Mode & Site Under Construction WordPress plugin before 1.8.2, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which h...
- Affected:
- up to 1.8.2
- Fixed in:
- 1.8.2
- Disclosed:
- May 14, 2021
CVE-2021-24191 on NVD →
Conditional Marketing Mailer for WooCommerce <= 1.5.2 - Cross-Site Request Forgery to Arbitrary Plugin Installation/Activation
high
The Conditional Marketing Mailer for WooCommerce Plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.2. This is due to missing or incorrect nonce validation on the 'cp_plugins_do_button_job_later_callback' AJAX action. This makes it possible for unauthenticated attacke...
- CVSS:
- 8.8
- Affected:
- up to 1.5.2
- Fixed in:
- 1.6
- Disclosed:
- Apr 22, 2021
WP Maintenance Mode & Site Under Construction <= 1.8.2 - Cross-Site Request Forgery to Arbitrary Plugin Installation/Activation
high
WP Maintenance Mode & Site Under Construction Plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.2. This is due to missing or incorrect nonce validation on the 'cp_plugins_do_button_job_later_callback' AJAX action. This makes it possible for unauthenticated attackers...
- CVSS:
- 8.8
- Affected:
- up to 1.8.2
- Fixed in:
- 1.9
- Disclosed:
- Apr 22, 2021
WP Maintenance Mode & Site Under Construction < 1.8.2 - Missing Authorization to Arbitrary Plugin Installation/Activation
high
Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WP Maintenance Mode & Site Under Construction WordPress plugin before 1.8.2, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps...
- CVSS:
- 8.8
- Affected:
- up to 1.8.2
- Fixed in:
- 1.8.2
- Disclosed:
- Apr 22, 2021
CVE-2021-24191 on NVD →
WooCommerce Conditional Marketing Mailer <= 1.5.1 - Improper Authorization
high
Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WooCommerce Conditional Marketing Mailer WordPress plugin before 1.5.2, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from the blog, which helps attack...
- CVSS:
- 8.8
- Affected:
- up to 1.5.2
- Fixed in:
- 1.5.2
- Disclosed:
- Apr 22, 2021
CVE-2021-24190 on NVD →
WP Maintenance Mode & Site Under Construction [wp-maintenance-mode-site-under-construction] < 1.6
unknown
The Conditional Marketing Mailer for WooCommerce Plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.2. This is due to missing or incorrect nonce validation on the 'cp_plugins_do_button_job_later_callback' AJAX action. This makes it possible for unauthenticated attacke...
- Affected:
- up to 1.6
- Fixed in:
- 1.6
- Disclosed:
- Apr 22, 2021
WP Maintenance Mode & Site Under Construction [wp-maintenance-mode-site-under-construction] < 1.9
unknown
WP Maintenance Mode & Site Under Construction Plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.2. This is due to missing or incorrect nonce validation on the 'cp_plugins_do_button_job_later_callback' AJAX action. This makes it possible for unauthenticated attackers...
- Affected:
- up to 1.9
- Fixed in:
- 1.9
- Disclosed:
- Apr 22, 2021
WP Maintenance Mode & Site Under Construction [wp-maintenance-mode-site-under-construction] < 1.9
unknown
The "cp_plugins_do_button_job_later_callback" AJAX action, from multiple plugins of the WP-Buy vendor, was lacking CSRF check, allowing attackers to make a logged in administrator install and active arbitrary plugins (including specific version) from the WordPress repository which could lead to more critical...
- Affected:
- up to 1.9
- Fixed in:
- 1.9
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database