CVE-2024-12683
- EPSS 0.07%
- Veröffentlicht 26.03.2025 06:15:28
- Zuletzt bearbeitet 06.05.2025 19:08:46
The Smart Maintenance Mode WordPress plugin before 1.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability i...
CVE-2025-1490
- EPSS 0.4%
- Veröffentlicht 26.03.2025 02:23:49
- Zuletzt bearbeitet 27.03.2025 16:45:46
The Smart Maintenance Mode plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘setstatus’ parameter in all versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping. This makes it possib...
CVE-2024-12682
- EPSS 0.07%
- Veröffentlicht 25.03.2025 06:00:11
- Zuletzt bearbeitet 06.05.2025 19:51:59
The Smart Maintenance Mode WordPress plugin before 1.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability i...