PT-2022-13979 · WordPress · Site Offline/Coming Soon/Maintenance Mode

Daniel Ruf

·

Published

2022-09-19

·

Updated

2022-09-21

·

CVE-2022-1580

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions The Site Offline Or Coming Soon Or Maintenance Mode WordPress plugin versions prior to 1.5.3
Description The plugin prevents users from accessing a website but does not do so if the URL contained certain keywords. Adding those keywords to the URL's query string would bypass the plugin's main feature.
Recommendations For versions prior to 1.5.3, update to version 1.5.3 or later to resolve the issue. As a temporary workaround, consider restricting access to URLs that contain specific keywords to minimize the risk of exploitation.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-1580

Affected Products

Site Offline/Coming Soon/Maintenance Mode