CVE-2022-1576 – WP Maintenance Mode & Coming Soon < 2.4.5 - Subscribed Users Deletion via CSRF
https://notcve.org/view.php?id=CVE-2022-1576
The WP Maintenance Mode & Coming Soon WordPress plugin before 2.4.5 is lacking CSRF when emptying the subscribed users list, which could allow attackers to make a logged in admin perform such action via a CSRF attack El plugin WP Maintenance Mode & Coming Soon de WordPress versiones anteriores a 2.4.5, carece de comprobación de tipo CSRF cuando vacía la lista de usuarios suscritos, lo que podría permitir a atacantes hacer que un administrador con sesión iniciada lleve a cabo dicha acción por medio de un ataque de tipo CSRF The WP Maintenance Mode & Coming Soon plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.4. This is due to missing nonce validation on the reset_plugin_settings, subscribers_empty_list, dismiss_notices, subscribers_export, add_subscriber, & send_contact functions. This makes it possible for unauthenticated attackers to perform a variety of actions such as emptying the subscribers list and resetting the plugin's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. • https://wpscan.com/vulnerability/68deab46-1c16-46ae-a912-a104958ca4cf • CWE-352: Cross-Site Request Forgery (CSRF) •