Conditional Maintenance Mode for WordPress Cross-Site Request Forgery Vulnerability
Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Conditional Maintenance Mode for WordPress plugin, affecting all versions up to and including 1.0.0. The vulnerability arises from a lack of nonce validation when changing the maintenance mode status, allowing unauthenticated attackers to manipulate the site's maintenance mode by sending a forged request, provided they can deceive an administrator into clicking a link.
Impact
Exploitation of this vulnerability allows for Cross-Site Request Forgery, where an attacker can trick an administrator into changing the site's maintenance mode status, potentially disrupting site availability or user experience.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
