Show filters
51 Total Results
Displaying 41-50 of 51
Sort by:
Attacker Value
Unknown
CVE-2021-36841
Disclosure Date: September 15, 2021 (last updated February 23, 2025)
Authenticated Stored Cross-Site Scripting (XSS) vulnerability in YITH Maintenance Mode (WordPress plugin) versions <= 1.3.7, vulnerable parameter &yith_maintenance_newsletter_submit_label. Possible even when unfiltered HTML is disallowed by WordPress configuration.
0
Attacker Value
Unknown
CVE-2021-24191
Disclosure Date: May 14, 2021 (last updated February 22, 2025)
Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WP Maintenance Mode & Site Under Construction WordPress plugin before 1.8.2, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attackers install vulnerable plugins and could lead to more critical vulnerabilities like RCE.
0
Attacker Value
Unknown
CVE-2020-15038
Disclosure Date: June 24, 2020 (last updated February 21, 2025)
The SeedProd coming-soon plugin before 5.1.1 for WordPress allows XSS.
0
Attacker Value
Unknown
CVE-2020-6166
Disclosure Date: January 09, 2020 (last updated February 21, 2025)
A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.15, allows authenticated users with basic access to export settings and change maintenance-mode themes.
0
Attacker Value
Unknown
CVE-2020-6168
Disclosure Date: January 09, 2020 (last updated February 21, 2025)
A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows authenticated users with basic access to enable and disable maintenance-mode settings (impacting the availability and confidentiality of a vulnerable site, along with the integrity of the setting).
0
Attacker Value
Unknown
CVE-2020-6167
Disclosure Date: January 09, 2020 (last updated February 21, 2025)
A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows a CSRF attack to enable maintenance mode, inject XSS, modify several important settings, or include remote files as a logo.
0
Attacker Value
Unknown
CVE-2015-9429
Disclosure Date: September 26, 2019 (last updated November 27, 2024)
The yith-maintenance-mode plugin before 1.2.0 for WordPress has CSRF with resultant XSS via the wp-admin/themes.php?page=yith-maintenance-mode panel_page parameter.
0
Attacker Value
Unknown
CVE-2018-20155
Disclosure Date: December 14, 2018 (last updated November 27, 2024)
The WP Maintenance Mode plugin before 2.0.7 for WordPress allows remote authenticated subscriber users to bypass intended access restrictions on changes to plugin settings.
0
Attacker Value
Unknown
CVE-2018-20156
Disclosure Date: December 14, 2018 (last updated November 27, 2024)
The WP Maintenance Mode plugin before 2.0.7 for WordPress allows remote authenticated "site administrator" users to execute arbitrary PHP code throughout a multisite network.
0
Attacker Value
Unknown
CVE-2018-20154
Disclosure Date: December 14, 2018 (last updated November 27, 2024)
The WP Maintenance Mode plugin before 2.0.7 for WordPress allows remote authenticated users to discover all subscriber e-mail addresses.
0