Show filters
31 Total Results
Displaying 21-30 of 31
Sort by:
Attacker Value
Unknown
CVE-2022-1576
Disclosure Date: July 11, 2022 (last updated October 07, 2023)
The WP Maintenance Mode & Coming Soon WordPress plugin before 2.4.5 is lacking CSRF when emptying the subscribed users list, which could allow attackers to make a logged in admin perform such action via a CSRF attack
0
Attacker Value
Unknown
CVE-2022-1945
Disclosure Date: June 20, 2022 (last updated October 07, 2023)
The Coming Soon & Maintenance Mode by Colorlib WordPress plugin before 1.0.99 does not sanitize and escape some settings, allowing high privilege users such as admin to perform Stored Cross-Site Scripting when unfiltered_html is disallowed (for example in multisite setup)
0
Attacker Value
Unknown
CVE-2022-0199
Disclosure Date: February 21, 2022 (last updated October 07, 2023)
The Coming soon and Maintenance mode WordPress plugin before 3.6.8 does not have CSRF check in its coming_soon_send_mail AJAX action, allowing attackers to make logged in admin to send arbitrary emails to all subscribed users via a CSRF attack
0
Attacker Value
Unknown
CVE-2022-0164
Disclosure Date: February 21, 2022 (last updated October 07, 2023)
The Coming soon and Maintenance mode WordPress plugin before 3.5.3 does not have authorisation and CSRF checks in its coming_soon_send_mail AJAX action, allowing any authenticated users, with a role as low as subscriber to send arbitrary emails to all subscribed users
0
Attacker Value
Unknown
CVE-2021-24539
Disclosure Date: November 01, 2021 (last updated February 23, 2025)
The Coming Soon, Under Construction & Maintenance Mode By Dazzler WordPress plugin before 1.6.7 does not sanitise or escape its description setting when outputting it in the frontend when the Coming Soon mode is enabled, even when the unfiltered_html capability is disallowed, leading to an authenticated Stored Cross-Site Scripting issue
0
Attacker Value
Unknown
CVE-2021-24577
Disclosure Date: October 11, 2021 (last updated February 23, 2025)
The Coming soon and Maintenance mode WordPress plugin before 3.5.3 does not properly sanitize inputs submitted by authenticated users when setting adding or modifying coming soon or maintenance mode pages, leading to stored XSS.
0
Attacker Value
Unknown
CVE-2021-24191
Disclosure Date: May 14, 2021 (last updated February 22, 2025)
Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WP Maintenance Mode & Site Under Construction WordPress plugin before 1.8.2, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attackers install vulnerable plugins and could lead to more critical vulnerabilities like RCE.
0
Attacker Value
Unknown
CVE-2020-15038
Disclosure Date: June 24, 2020 (last updated February 21, 2025)
The SeedProd coming-soon plugin before 5.1.1 for WordPress allows XSS.
0
Attacker Value
Unknown
CVE-2020-6166
Disclosure Date: January 09, 2020 (last updated February 21, 2025)
A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.15, allows authenticated users with basic access to export settings and change maintenance-mode themes.
0
Attacker Value
Unknown
CVE-2020-6168
Disclosure Date: January 09, 2020 (last updated February 21, 2025)
A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows authenticated users with basic access to enable and disable maintenance-mode settings (impacting the availability and confidentiality of a vulnerable site, along with the integrity of the setting).
0