Extension WordPress
Vulnérabilités WP Maintenance
Cette page rassemble les failles publiées pour WP Maintenance, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WP Maintenance
7 fiches
WP Maintenance <= 6.1.9.7 – Authenticated (Administrator+) PHP Object Injection
The WP Maintenance plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 6.1.9.7 via deserialization of untrusted input via the wpm_process_settings_export() function. This makes it possible for authenticated attackers, with administrator-level access…
*-6.1.9.7
6.1.9.8
07/05/2025
WP Maintenance <= 6.1.9.2 – IP Spoofing to Maintenance Mode Bypass
The WP Maintenance plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 6.1.9.2 due to insufficient IP address validation and use of user-supplied HTTP headers as a primary method for IP…
*-6.1.9.2
6.1.9.3
18/06/2024
WP Maintenance <= 6.1.6 – Information Exposure
The WP Maintenance plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 6.1.6 via the REST API. This makes it possible for unauthenticated attackers to bypass the plugin's maintenance mode obtain post…
*-6.1.6
6.1.7
16/02/2024
WP Maintenance <= 6.1.3 – IP Restriction Bypass
The WP Maintenance plugin for WordPress is vulnerable to IP Address Restriction Bypass in versions up to, and including, 6.1.3. This can be used to bypass settings that may have blocked out an IP address from accessing a…
*-6.1.3
6.1.4
14/11/2023
WP Maintenance <= 6.0.7 – Authenticated (Admin+) Cross-Site Scripting
The WP Maintenance plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 6.0.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative permissions and above…
*-6.0.7
6.0.8
28/06/2022
WP Maintenance <= 6.0.5 – Authenticated (Admin+) Stored Cross-Site Scripting
The WP Maintenance plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with admin-level permissions and…
*-6.0.5
6.0.6
15/04/2022
WP Maintenance <= 5.0.5 – Cross-Site Request Forgery to Stored Cross-Site Scripting
A flaw in the WordPress plugin, WP Maintenance before 5.0.6, allowed attackers to enable a vulnerable site's maintenance mode and inject malicious code affecting site visitors. There was CSRF with resultant XSS.
*-5.0.5
5.0.6
19/11/2019
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.