Cross-Site Request Forgery in WP Maintenance Mode for WordPress
CVE-2013-3250
Currently unrated
Summary
The WP Maintenance Mode plugin for WordPress is susceptible to a Cross-Site Request Forgery (CSRF) vulnerability that allows attackers to exploit the authentication of legitimate users. By crafting a malicious request, these remote attackers can manipulate the plugin's settings without the user's consent. This can lead to unauthorized alterations that may compromise the integrity and security of the website, making it imperative for users to update to version 1.8.8 or later to mitigate this risk.
References
Timeline
Vulnerability Reserved
Vulnerability published