Cross-Site Request Forgery in Conditional Maintenance Mode for WordPress Plugin
CVE-2025-12586

4.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
25 November 2025

What is CVE-2025-12586?

The Conditional Maintenance Mode plugin for WordPress contains a vulnerability that allows an unauthenticated attacker to exploit the system's maintenance mode feature. This issue arises from the absence of proper nonce validation when altering the maintenance mode status. Attackers can manipulate the system by tricking an administrator into clicking a specially crafted link, subsequently enabling or disabling the maintenance mode without authorization. It's essential for users to take action to secure their WordPress installations against this vulnerability.

Affected Version(s)

Conditionnal Maintenance Mode for WordPress * <= 1.0.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

dayea song
.