Input validation vulnerability in Coming soon and Maintenance mode 3.6.8

A security issue has been found in the Coming Soon and Maintenance Mode WordPress plugin before version 3.6.8. This issue could allow attackers to send emails to all subscribed users without the logged in admin’s knowledge. The issue is caused by a lack of a security check (known as a CSRF check) in the plugin’s AJAX action.

Detected in:

Coming soon and Maintenance mode fixed vulnerable versions: >= * < 3.6.8

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.