Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2020-36707: Coming Soon & Maintenance Mode Page

The Coming Soon & Maintenance Mode Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.57. This is due to confusing logic functions missing or having incorrect nonce validation. This makes it possible for unauthenticated attackers to gain and perform otherwise unauthorized access and actions via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE
#csrf#vulnerability#web#wordpress#auth

Coming Soon & Maintenance Mode Page: Plugin Details

Coming Soon & Maintenance Mode Page: Security Information

Insecure versions:

Up To 1.57

Known since:

2020-09-17 21:12:23

Description:

The plugins only check the CSRF nonce if it has been provided, making them vulnerable to CSRF attacks if the nonce is removed.

Coming Soon & Maintenance Mode Page: Safety Recommendations

We have rated Coming Soon & Maintenance Mode Page as Good (current version safe) which means that we have found vulnerabilities in older versions.

We recommend that you only use the latest version of Coming Soon & Maintenance Mode Page.

Coming Soon & Maintenance Mode Page: Staying Up-to-date

Make sure your installation of Coming Soon & Maintenance Mode Page is safe with the following free Jetpack services for WordPress sites:

  • Updates & Management
    Turn on auto-updates for Coming Soon & Maintenance Mode Page or manage in bulk.
  • Prevent Infiltrations
    Automatic protection against brute force attacks and secure sign on.

Choose Your Plan

Coming Soon & Maintenance Mode Page: Keeping Safe

If you’re running a business, ecommerce, news, or other critical website, Jetpack also provides additional indispensable services:

  • Automated Backups
    Full backup of your entire site with unlimited storage space.
  • Restores & Migrations
    Restore or migrate your site from a backup with one click.
  • Security Scanning
    Regular, automated scans of your site for malware, threats, and hacks.
  • Expert Support
    Fast, priority support for any WordPress security issue.

Choose Your Plan

About this information

This WordPress security information is part of our security library and is brought to you by Jetpack as part of our committment to a safer WordPress experience.

If you have any questions, please do not hesitate to contact us.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda