← back
CVE-2022-1576CWE-352

WP Maintenance Mode & Coming Soon < 2.4.5 - Subscribed Users Deletion via CSRF

3Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 0.5%
exploitation probability
0.5%top 60% of all CVEs
observed exploitation
nono source reports it
The WP Maintenance Mode & Coming Soon WordPress plugin before 2.4.5 is lacking CSRF when emptying the subscribed users list, which could allow attackers to make a logged in admin perform such action via a CSRF attack