Vulnerabilities > WP Maintenance Project

DATE CVE VULNERABILITY TITLE RISK
2022-04-15 CVE-2021-36828 Cross-site Scripting vulnerability in WP Maintenance Project WP Maintenance
Authenticated (admin+) Stored Cross-Site Scripting (XSS) in WP Maintenance plugin <= 6.0.7 versions.
network
low complexity
wp-maintenance-project CWE-79
4.8
2019-12-26 CVE-2019-19979 Cross-Site Request Forgery (CSRF) vulnerability in WP Maintenance Project WP Maintenance
A flaw in the WordPress plugin, WP Maintenance before 5.0.6, allowed attackers to enable a vulnerable site's maintenance mode and inject malicious code affecting site visitors.
6.8