Cross-Site Request Forgery in Conditional Maintenance Mode for WordPress Plugin
CVE-2025-12586
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 25 November 2025
What is CVE-2025-12586?
The Conditional Maintenance Mode plugin for WordPress contains a vulnerability that allows an unauthenticated attacker to exploit the system's maintenance mode feature. This issue arises from the absence of proper nonce validation when altering the maintenance mode status. Attackers can manipulate the system by tricking an administrator into clicking a specially crafted link, subsequently enabling or disabling the maintenance mode without authorization. It's essential for users to take action to secure their WordPress installations against this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Conditionnal Maintenance Mode for WordPress * <= 1.0.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved