Description
WordPress Plugin WP Maintenance Mode & Site Under Construction is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently install arbitrary plugins. WordPress Plugin WP Maintenance Mode & Site Under Construction version 1.8.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.8.2 or latest
References
Related Vulnerabilities
MongoDb Reachable Assertion Vulnerability (CVE-2026-5170)
WordPress Plugin Photoracer Multiple Cross-Site Scripting and SQL Injection Vulnerabilities (1.0)
MySQL CVE-2016-8287 Vulnerability (CVE-2016-8287)
WordPress Plugin NextGEN Gallery-WordPress Gallery 'xml/media-rss.php' Cross-Site Scripting (1.5.1)