Description
Cross-Site Request Forgery (CSRF) vulnerability in RSTheme Ultimate Coming Soon & Maintenance ultimate-coming-soon allows Cross Site Request Forgery.This issue affects Ultimate Coming Soon & Maintenance: from n/a through <= 1.0.9.
Published: 2025-01-24
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A Cross‑Site Request Forgery flaw exists in RSTheme Ultimate Coming Soon & Maintenance. The vulnerability allows an attacker to trigger any action that the authenticated WordPress user can execute via the plugin, potentially changing site configuration, disabling the maintenance mode, or altering plugin settings without the user’s explicit consent. The weakness is identified as CWE‑352 and may compromise the integrity of the site’s configuration, and where attacker privileges are high, may also lead to further compromise of the underlying WordPress installation.

Affected Systems

The issue affects all installations of RSTheme Ultimate Coming Soon & Maintenance up to and including version 1.0.9. WordPress sites that rely on this plugin for downtime messaging or site protection are therefore vulnerable.

Risk and Exploitability

With a CVSS score of 5.4 the flaw is considered moderate. The EPSS score of less than 1% indicates that, at present, the likelihood of exploitation is low, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be a crafted HTTP request sent from a malicious website or spam link that submits an authenticated request to the plugin without requiring a valid CSRF token. Successful exploitation would require the user to be logged in and may be easier against administrators or users with higher privileges.

Generated by OpenCVE AI on May 1, 2026 at 18:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update RSTheme Ultimate Coming Soon & Maintenance to the latest version (1.1 or newer) where the CSRF protection is added.
  • If an immediate update is not feasible, deactivate or remove the plugin entirely until a fixed version is installed.
  • As a temporary safeguard, enforce strict CSRF checks on all plugin endpoints—require a legitimate nonce or authentication token for state‑changing actions—and consider deploying a web application firewall rule set to block anonymous POST requests to the plugin’s administrative URLs.

Generated by OpenCVE AI on May 1, 2026 at 18:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3757 Cross-Site Request Forgery (CSRF) vulnerability in RSTheme Ultimate Coming Soon & Maintenance allows Cross Site Request Forgery. This issue affects Ultimate Coming Soon & Maintenance: from n/a through 1.0.9.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in RSTheme Ultimate Coming Soon & Maintenance allows Cross Site Request Forgery. This issue affects Ultimate Coming Soon & Maintenance: from n/a through 1.0.9. Cross-Site Request Forgery (CSRF) vulnerability in RSTheme Ultimate Coming Soon & Maintenance ultimate-coming-soon allows Cross Site Request Forgery.This issue affects Ultimate Coming Soon & Maintenance: from n/a through <= 1.0.9.
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L'}


Mon, 09 Jun 2025 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Rstheme
Rstheme ultimate Coming Soon \& Maintenance
CPEs cpe:2.3:a:rstheme:ultimate_coming_soon_\&_maintenance:*:*:*:*:*:*:*:*
Vendors & Products Rstheme
Rstheme ultimate Coming Soon \& Maintenance

Fri, 24 Jan 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Jan 2025 17:30:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in RSTheme Ultimate Coming Soon & Maintenance allows Cross Site Request Forgery. This issue affects Ultimate Coming Soon & Maintenance: from n/a through 1.0.9.
Title WordPress Ultimate Coming Soon & Maintenance plugin <= 1.0.9 - Cross Site Request Forgery (CSRF) vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L'}


Subscriptions

Rstheme Ultimate Coming Soon \& Maintenance
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-11T23:13:27.349Z

Reserved: 2025-01-23T14:50:18.328Z

Link: CVE-2025-24546

cve-icon Vulnrichment

Updated: 2025-01-24T18:48:05.449Z

cve-icon NVD

Status : Modified

Published: 2025-01-24T18:15:32.893

Modified: 2026-04-23T15:24:58.630

Link: CVE-2025-24546

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T19:00:08Z

Weaknesses