Extension WordPress
Vulnérabilités WP Maintenance Mode & Site Under Construction
Cette page rassemble les failles publiées pour WP Maintenance Mode & Site Under Construction, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WP Maintenance Mode & Site Under Construction
5 fiches
WP Maintenance Mode & Site Under Construction <= 4.3 – Cross-Site Request Forgery
The WP Maintenance Mode & Site Under Construction plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.3. This is due to missing or incorrect nonce validation on a function. This…
*-4.3
4.4
05/06/2025
WP Maintenance Mode & Site Under Construction <= 1.8.2 – Cross-Site Request Forgery to Arbitrary Plugin Installation/Activation
WP Maintenance Mode & Site Under Construction Plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.2. This is due to missing or incorrect nonce validation on the 'cp_plugins_do_button_job_later_callback' AJAX action. This…
*-1.8.2
1.9
22/04/2021
WP Maintenance Mode & Site Under Construction < 1.8.2 – Missing Authorization to Arbitrary Plugin Installation/Activation
Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WP Maintenance Mode & Site Under Construction WordPress plugin before 1.8.2, to install any plugin (including a specific version) from the WordPress repository, as well as activate…
[*, 1.8.2)
1.8.2
22/04/2021
WooCommerce Conditional Marketing Mailer <= 1.5.1 – Improper Authorization
Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WooCommerce Conditional Marketing Mailer WordPress plugin before 1.5.2, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from…
[*, 1.5.2)
1.5.2
22/04/2021
Conditional Marketing Mailer for WooCommerce <= 1.5.2 – Cross-Site Request Forgery to Arbitrary Plugin Installation/Activation
The Conditional Marketing Mailer for WooCommerce Plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.2. This is due to missing or incorrect nonce validation on the 'cp_plugins_do_button_job_later_callback' AJAX action. This makes…
*-1.5.2
1.6
22/04/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.