Extension WordPress

Vulnérabilités Minimal Coming Soon – Coming Soon Page

Cette page rassemble les failles publiées pour Minimal Coming Soon – Coming Soon Page, leurs plages de versions affectées et les correctifs signalés dans la base locale.

7Vulnérabilités
0Critiques
7Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Minimal Coming Soon – Coming Soon Page

7 fiches

CVE-2024-5087 Moyenne · 6,3
Minimal Coming Soon – Coming Soon Page

Minimal Coming Soon – Coming Soon Page <= 2.38 – Missing Authorization to Limited Settings Change

The Minimal Coming Soon – Coming Soon Page plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the validate_ajax, deactivate_ajax, and save_ajax functions in all versions up to, and including,…

Versions affectées

*-2.38

Correctif

2.39

Publication

07/06/2024

Vulnérabilité Moyenne · 5,5
Minimal Coming Soon – Coming Soon Page

Minimal Coming Soon – Coming Soon Page <= 2.33 – Authenticated (Administrator+) Cross-Site Scripting

The Minimal Coming Soon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘custom_css’ and 'custom_html' parameters in versions up to, and including, 2.33 due to insufficient input sanitization and output escaping. This makes it possible…

Versions affectées

*-2.33

Correctif

2.35

Publication

21/11/2022

Vulnérabilité Moyenne · 5,5
Minimal Coming Soon – Coming Soon Page

Minimal Coming Soon – Coming Soon Page <= 2.33 – Authenticated (Admin+) Stored Cross-Site Scripting

The Minimal Coming Soon – Coming Soon Page plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom_css value in versions up to, and including, 2.33 due to insufficient input sanitization and output escaping. This makes…

Versions affectées

*-2.34

Correctif

2.35

Publication

05/08/2022

CVE-2020-6167 Élevée · 8,8
Minimal Coming Soon – Coming Soon Page

Minimal Coming Soon & Maintenance Mode <= 2.10 – Cross-Site Request Forgery to Stored Cross-Site Scripting and Setting Changes

A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows a CSRF attack to enable maintenance mode, inject XSS, modify several important settings, or include remote files as a logo.

Versions affectées

*-2.10

Correctif

2.15

Publication

08/01/2020

CVE-2020-6168 Élevée · 7,1
Minimal Coming Soon – Coming Soon Page

Minimal Coming Soon & Maintenance Mode <= 2.10 – Missing Authorization

A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows authenticated users with basic access to enable and disable maintenance-mode settings (impacting the availability and confidentiality of a vulnerable site, along with the…

Versions affectées

[*, 2.15)

Correctif

2.15

Publication

18/12/2019

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités