Flaw in WP Maintenance Plugin Allows Code Injection Affecting WordPress Sites
CVE-2019-19979

8.8HIGH

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
26 December 2019

Summary

A security flaw in the WP Maintenance plugin for WordPress, specifically versions before 5.0.6, enables attackers to exploit a weakness in its maintenance mode. This vulnerability allows unauthorized users to toggle maintenance mode, potentially injecting malicious scripts that affect site visitors. The issue arises from a combination of cross-site request forgery (CSRF) and cross-site scripting (XSS) vulnerabilities, leading to serious implications for site integrity and user safety.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.