CVE-2022-1576: WP Maintenance Mode & Coming Soon < 2.4.5 - Subscribed Users Deletion via CSRF
The WP Maintenance Mode & Coming Soon WordPress plugin before 2.4.5 is lacking CSRF when emptying the subscribed users list, which could allow attackers to make a logged in admin perform such action via a CSRF attack
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-1576?
The severity of CVE-2022-1576 is medium with a severity value of 6.5.
How does the WP Maintenance Mode & Coming Soon plugin vulnerability allow attackers to perform an action?
The WP Maintenance Mode & Coming Soon plugin vulnerability allows attackers to make a logged in admin perform an action via a CSRF attack.
How can an attacker exploit the CSRF vulnerability in the WP Maintenance Mode & Coming Soon plugin?
An attacker can exploit the CSRF vulnerability in the WP Maintenance Mode & Coming Soon plugin by tricking a logged in admin into clicking on a malicious link or visiting a specially crafted website.
What software versions are affected by the CVE-2022-1576 vulnerability?
The CVE-2022-1576 vulnerability affects the WP Maintenance Mode & Coming Soon WordPress plugin versions up to and excluding 2.4.5.
Is there a fix available for the CVE-2022-1576 vulnerability?
Yes, the fix for the CVE-2022-1576 vulnerability is to update the WP Maintenance Mode & Coming Soon plugin to version 2.4.5 or later.