Description
The Hostinger plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability check on the function publish_website in all versions up to, and including, 1.9.7. This makes it possible for unauthenticated attackers to enable and disable maintenance mode.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-58964 | The Hostinger plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability check on the function publish_website in all versions up to, and including, 1.9.7. This makes it possible for unauthenticated attackers to enable and disable maintenance mode. |
References
History
Wed, 08 Apr 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Hostinger <= 1.9.7 - Missing Authorization to Maintenance Mode Activation |
Tue, 17 Jun 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:26:55.018Z
Reserved: 2023-12-12T20:22:36.491Z
Link: CVE-2023-6751
Updated: 2024-08-02T08:42:07.326Z
Status : Modified
Published: 2024-01-11T09:15:51.817
Modified: 2026-04-08T19:18:59.783
Link: CVE-2023-6751
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD