High severity8.8NVD Advisory· Published Jun 7, 2023· Updated Apr 8, 2026
CVE-2020-36707
CVE-2020-36707
Description
The Coming Soon & Maintenance Mode Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.57. This is due to confusing logic functions missing or having incorrect nonce validation. This makes it possible for unauthenticated attackers to gain and perform otherwise unauthorized access and actions via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected products
1- cpe:2.3:a:wpconcern:nifty_coming_soon_\&_maintenance_mode_page:*:*:*:*:*:wordpress:*:*Range: <1.58
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- wpscan.com/vulnerability/aa47a464-af97-43bc-b6cb-75a08ce3ece7nvdThird Party Advisory
- www.acunetix.com/vulnerabilities/web/wordpress-plugin-coming-soon-maintenance-mode-page-cross-site-request-forgery-1-57/nvdThird Party Advisory
- www.wordfence.com/threat-intel/vulnerabilities/id/59278214-b0ce-44bf-8d8f-265c5c50006anvdThird Party Advisory
- jetpack.com/features/security/library/nifty-coming-soon-and-under-construction-page-plugin/nvdProduct
News mentions
0No linked articles in our index yet.