What the vulnerability does
01Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Weblizar Coming Soon Page – Responsive Coming Soon & Maintenance Mode allows SQL Injection.This issue affects Coming Soon Page – Responsive Coming Soon & Maintenance Mode: from n/a through 1.5.9.
Explanation of Vulnerability in Simple Terms
02Summary
The Coming Soon Page plugin for WordPress contains a SQL injection vulnerability in versions up to 1.5.9. An attacker with high-level site privileges can inject malicious SQL commands to read sensitive database information. The vulnerability requires administrator or equivalent access to exploit. Site owners should update to a version newer than 1.5.9 immediately.
What an attacker can do
03Attacker Capabilities
Read sensitive data from the site's database by injecting SQL commands.
Potential impact on your site
04Site Impact
A malicious admin or compromised admin account can extract sensitive database records without leaving obvious traces.
Conditions required to exploit
05Prerequisites
Attacker must have high-level site privileges (administrator or equivalent role).
Key dates
06Disclosure timeline
November 6, 2023
CVE published
April 29, 2026
Record updated