VYPR

Yith Maintenance Mode

by Yithemes

CVEs (3)

  • CVE-2021-36845MedSep 27, 2021
    risk 0.45cvss 6.9epss 0.01

    Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities in YITH Maintenance Mode (WordPress plugin) versions <= 1.3.8, there are 46 vulnerable parameters that were missed by the vendor while patching the 1.3.7 version to 1.3.8. Vulnerable parameters: 1 -…

  • CVE-2021-36841MedSep 27, 2021
    risk 0.45cvss 6.9epss 0.01

    Authenticated Stored Cross-Site Scripting (XSS) vulnerability in YITH Maintenance Mode (WordPress plugin) versions <= 1.3.7, vulnerable parameter &yith_maintenance_newsletter_submit_label. Possible even when unfiltered HTML is disallowed by WordPress configuration.

  • CVE-2015-9429MedSep 26, 2019
    risk 0.42cvss 6.5epss 0.01

    The yith-maintenance-mode plugin before 1.2.0 for WordPress has CSRF with resultant XSS via the wp-admin/themes.php?page=yith-maintenance-mode panel_page parameter.