Description
WordPress Plugin Coming Soon/Maintenance mode Ready! is prone to a cross-site request forgery vulnerability. Exploiting this issue may allow a remote attacker to perform certain administrative actions and gain unauthorized access to the affected application; other attacks are also possible. WordPress Plugin Coming Soon/Maintenance mode Ready! version 0.5.0 is vulnerable; other versions may also be affected.
Remediation
Edit the source code to ensure that CSRF protection is implemented with Nonce-like mechanism
References
Related Vulnerabilities
ATutor Improper Authentication Vulnerability (CVE-2014-9753)
Apache HTTP Server Other Vulnerability (CVE-1999-1199)
WordPress Plugin YITH WooCommerce Authorize.net Payment Gateway Security Bypass (1.1.12)
Oracle JRE CVE-2013-5803 Vulnerability (CVE-2013-5803)
Internet Information Services Other Vulnerability (CVE-2000-0858)