First published: Mon Jul 11 2022(Updated: )
The WP Maintenance Mode & Coming Soon WordPress plugin before 2.4.5 is lacking CSRF when emptying the subscribed users list, which could allow attackers to make a logged in admin perform such action via a CSRF attack
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Themeisle Wp Maintenance Mode \& Coming Soon | <2.4.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-1576 is medium with a severity value of 6.5.
The WP Maintenance Mode & Coming Soon plugin vulnerability allows attackers to make a logged in admin perform an action via a CSRF attack.
An attacker can exploit the CSRF vulnerability in the WP Maintenance Mode & Coming Soon plugin by tricking a logged in admin into clicking on a malicious link or visiting a specially crafted website.
The CVE-2022-1576 vulnerability affects the WP Maintenance Mode & Coming Soon WordPress plugin versions up to and excluding 2.4.5.
Yes, the fix for the CVE-2022-1576 vulnerability is to update the WP Maintenance Mode & Coming Soon plugin to version 2.4.5 or later.