CVE-2023-49842: WordPress Rocket Maintenance Mode & Coming Soon Page Plugin <= 4.3 is vulnerable to Cross Site Scripting (XSS)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpexpertsio Rocket Maintenance Mode & Coming Soon Page allows Stored XSS.This issue affects Rocket Maintenance Mode & Coming Soon Page: from n/a through 4.3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-49842?
CVE-2023-49842 is classified as a Stored Cross-Site Scripting (XSS) vulnerability.
How do I fix CVE-2023-49842?
To fix CVE-2023-49842, update the Rocket Maintenance Mode & Coming Soon Page plugin to version 4.4 or later.
What impact does CVE-2023-49842 have on affected installations?
CVE-2023-49842 allows attackers to store malicious scripts, which can execute in the browsers of users with access to the affected site.
Which versions of the software are affected by CVE-2023-49842?
CVE-2023-49842 affects all versions of the Rocket Maintenance Mode & Coming Soon Page plugin up to and including 4.3.
Who is primarily affected by CVE-2023-49842?
Websites using the affected versions of the Rocket Maintenance Mode & Coming Soon Page plugin are primarily at risk due to CVE-2023-49842.