PT-2022-13990 · WordPress · The Site Offline/Coming Soon

Daniel Ruf

·

Published

2022-06-27

·

Updated

2022-10-05

·

CVE-2022-1593

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions The Site Offline or Coming Soon WordPress plugin versions 1.6.6 and earlier
Description The issue is related to the lack of CSRF check when updating settings, as well as insufficient sanitisation and escaping in some settings. This allows attackers to make a logged-in admin change settings and inject Cross-Site Scripting payloads via a CSRF attack.
Recommendations For The Site Offline or Coming Soon WordPress plugin versions 1.6.6 and earlier, update to a version that includes a CSRF check and proper sanitisation and escaping of settings to prevent Cross-Site Scripting attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-1593

Affected Products

The Site Offline/Coming Soon