Headline
CVE-2020-36707: Coming Soon & Maintenance Mode Page
The Coming Soon & Maintenance Mode Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.57. This is due to confusing logic functions missing or having incorrect nonce validation. This makes it possible for unauthenticated attackers to gain and perform otherwise unauthorized access and actions via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Coming Soon & Maintenance Mode Page: Plugin Details
Coming Soon & Maintenance Mode Page: Security Information
Insecure versions:
Up To 1.57
Known since:
2020-09-17 21:12:23
Description:
The plugins only check the CSRF nonce if it has been provided, making them vulnerable to CSRF attacks if the nonce is removed.
Coming Soon & Maintenance Mode Page: Safety Recommendations
We have rated Coming Soon & Maintenance Mode Page as Good (current version safe) which means that we have found vulnerabilities in older versions.
We recommend that you only use the latest version of Coming Soon & Maintenance Mode Page.
Coming Soon & Maintenance Mode Page: Staying Up-to-date
Make sure your installation of Coming Soon & Maintenance Mode Page is safe with the following free Jetpack services for WordPress sites:
- Updates & Management
Turn on auto-updates for Coming Soon & Maintenance Mode Page or manage in bulk. - Prevent Infiltrations
Automatic protection against brute force attacks and secure sign on.
Choose Your Plan
Coming Soon & Maintenance Mode Page: Keeping Safe
If you’re running a business, ecommerce, news, or other critical website, Jetpack also provides additional indispensable services:
- Automated Backups
Full backup of your entire site with unlimited storage space. - Restores & Migrations
Restore or migrate your site from a backup with one click. - Security Scanning
Regular, automated scans of your site for malware, threats, and hacks. - Expert Support
Fast, priority support for any WordPress security issue.
Choose Your Plan
About this information
This WordPress security information is part of our security library and is brought to you by Jetpack as part of our committment to a safer WordPress experience.
If you have any questions, please do not hesitate to contact us.