Impact
The described flaw is a CSRF vulnerability in the WP Maintenance Mode & Site Under Construction plugin through version 4.3. It allows a malicious site or attacker to submit requests to the WordPress site that are accepted and executed by the plugin, potentially affecting plugin state or configuration. Based on the nature of CSRF, an attacker could force an authenticated user to trigger plugin actions without the user’s intent, thereby impacting the integrity of the site configuration.
Affected Systems
WordPress installations that use the WP Maintenance Mode & Site Under Construction plugin version 4.3 or older are affected. The vulnerability is present in all releases of the plugin up to and including 4.3, regardless of WordPress core version.
Risk and Exploitability
The CVSS score of 4.3 places this issue in the moderate risk range, while the EPSS score of <1% indicates a low current probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation would generally require an attacker to entice a logged‑in user with sufficient privileges to visit a malicious URL, causing the browser to send a request that the plugin accepts because it does not validate an anti‑CSRF token or other provenance checks.
OpenCVE Enrichment
EUVD