CVE-2026-81295: WordPress Under Construction plugin <= 5.82 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in Under Construction <= 5.82 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Under Construction pluginto a version that resolves this vulnerability.Fixed in 5.83
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The issue is described as unauthenticated XSS, so an attacker does not need an account or other authenticated access to the affected WordPress site. Exploitation still requires user interaction, as indicated by the UI:R vector.
Who is exposed?
Sites using the WordPress Under Construction plugin at version 5.82 or earlier are in scope based on the affected-version information provided. The network attack vector indicates the vulnerable functionality may be reachable remotely.
How serious is successful exploitation?
The vulnerability is rated high with a CVSS score of 7.1. Its vector indicates low impacts to confidentiality, integrity, and availability, with scope changed.