Input validation vulnerability in Site Offline Or Coming Soon Or Maintenance Mode 1.5.6

The [Site Offline Or Coming Soon Or Maintenance Mode] plugin for WordPress is not secure in versions 1.5.6 and below. This plugin is only found on multi-site installations or installations where a setting called [unfiltered_html] has been disabled. An attacker with administrator-level permissions can inject web scripts into certain pages. Whenever someone visits these pages, the injected web scripts will execute, potentially allowing the attacker to access sensitive information or perform malicious activities.

Detected in:

Site Offline Or Coming Soon Or Maintenance Mode open vulnerable versions: >= * <= 1.5.6

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.