Search
Search Results (4 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2024-0789 | 2 Wordpress, Wp Maintenance Project | 2 Wordpress, Wp Maintenance | 2025-07-12 | 5.3 Medium |
| The WP Maintenance plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 6.1.9.2 due to insufficient IP address validation and use of user-supplied HTTP headers as a primary method for IP retrieval. This makes it possible for unauthenticated attackers to bypass maintenance mode. | ||||
| CVE-2021-36828 | 1 Wp Maintenance Project | 1 Wp Maintenance | 2025-04-23 | 4.8 Medium |
| Authenticated (admin+) Stored Cross-Site Scripting (XSS) in WP Maintenance plugin <= 6.0.7 versions. | ||||
| CVE-2022-30536 | 1 Wp Maintenance Project | 1 Wp Maintenance | 2025-02-20 | 3.4 Low |
| Authenticated Stored Cross-Site Scripting (XSS) vulnerability in Florent Maillefaud's WP Maintenance plugin <= 6.0.7 at WordPress. | ||||
| CVE-2019-19979 | 1 Wp Maintenance Project | 1 Wp Maintenance | 2024-11-21 | 8.8 High |
| A flaw in the WordPress plugin, WP Maintenance before 5.0.6, allowed attackers to enable a vulnerable site's maintenance mode and inject malicious code affecting site visitors. There was CSRF with resultant XSS. | ||||
Page 1 of 1.