First published: Mon Oct 11 2021(Updated: )
The Coming soon and Maintenance mode WordPress plugin before 3.5.3 does not properly sanitize inputs submitted by authenticated users when setting adding or modifying coming soon or maintenance mode pages, leading to stored XSS.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Wpdevart Coming Soon And Maintenance Mode | <3.5.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2021-24577.
The severity level of CVE-2021-24577 is medium.
The affected software of CVE-2021-24577 is the Coming soon and Maintenance mode WordPress plugin before version 3.5.3.
CVE-2021-24577 is a vulnerability in the Coming soon and Maintenance mode WordPress plugin before version 3.5.3 that allows authenticated users to submit unproperly sanitized inputs, leading to stored cross-site scripting (XSS).
Yes, updating the Coming soon and Maintenance mode WordPress plugin to version 3.5.3 or newer fixes CVE-2021-24577.