Cross-Site Request Forgery in WP Maintenance Mode for WordPress
CVE-2013-3250

Currently unrated

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
21 June 2013

Summary

The WP Maintenance Mode plugin for WordPress is susceptible to a Cross-Site Request Forgery (CSRF) vulnerability that allows attackers to exploit the authentication of legitimate users. By crafting a malicious request, these remote attackers can manipulate the plugin's settings without the user's consent. This can lead to unauthorized alterations that may compromise the integrity and security of the website, making it imperative for users to update to version 1.8.8 or later to mitigate this risk.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.