Vulnerability CVE-2022-1593


Published: 2022-06-27

Description:
The Site Offline or Coming Soon WordPress plugin through 1.6.6 does not have CSRF check in place when updating its settings, and it also lacking sanitisation as well as escaping in some of them. As a result, attackers could make a logged in admin change them and put Cross-Site Scripting payloads in them via a CSRF attack

Type:

CWE-352

(Cross-Site Request Forgery (CSRF))

 References:
https://wpscan.com/vulnerability/67678666-402b-4010-ac56-7067a0f40185

Copyright 2026, cxsecurity.com

 

Back to Top