Extension WordPress
Vulnérabilités Coming soon and Maintenance mode
Cette page rassemble les failles publiées pour Coming soon and Maintenance mode, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Coming soon and Maintenance mode
4 fiches
Coming soon and Maintenance mode <= 3.7.3 – IP Address Spoofing via get_real_ip
The Coming soon and Maintenance mode plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 3.7.3 due to the use of user-supplied HTTP headers as a primary method for IP retrieval.…
*-3.7.3
3.7.4
01/12/2023
Coming soon and Maintenance mode <= 3.6.6 – Missing Authorization to Arbitrary Email Send
The Coming soon and Maintenance mode WordPress plugin before 3.6.8 does not have authorisation and CSRF checks in its coming_soon_send_mail AJAX action, allowing any authenticated users, with a role as low as subscriber to send arbitrary emails to…
*-3.6.6
3.6.7
24/01/2022
Coming soon and Maintenance mode <= 3.6.7 – Cross-Site request Forgery to Arbitrary Email Send
The Coming soon and Maintenance mode WordPress plugin before 3.6.8 does not have CSRF check in its coming_soon_send_mail AJAX action, allowing attackers to make logged in admin to send arbitrary emails to all subscribed users via a CSRF…
[*, 3.6.8)
3.6.8
23/01/2022
Coming soon and Maintenance mode <= 3.5.2 – Authenticated Stored Cross-Site Scripting
The Coming soon and Maintenance mode WordPress plugin before 3.5.3 does not properly sanitize inputs submitted by authenticated users when setting adding or modifying coming soon or maintenance mode pages, leading to stored XSS.
[*, 3.5.3)
3.5.3
13/09/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.