What the vulnerability does
01Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chandra Shekhar Sahu Site Offline Or Coming Soon Or Maintenance Mode allows Stored XSS.This issue affects Site Offline Or Coming Soon Or Maintenance Mode: from n/a through 1.5.6.
Explanation of Vulnerability in Simple Terms
02Summary
A stored cross-site scripting (XSS) vulnerability exists in Site Offline Or Coming Soon Or Maintenance Mode through version 1.5.6. An authenticated administrator with high privileges can inject malicious scripts that execute in the browsers of site visitors, potentially stealing session tokens or redirecting users. The vulnerability requires the admin to craft a malicious input and a user to view the affected page.
What an attacker can do
03Attacker Capabilities
Inject malicious JavaScript that runs in visitors' browsers when they view the site.
Potential impact on your site
04Site Impact
Malicious admins can compromise visitor sessions, steal credentials, or redirect users to phishing sites.
Conditions required to exploit
05Prerequisites
Attacker must have high-level admin privileges and a visitor must view the page containing the injected script.
Key dates
06Disclosure timeline
December 15, 2023
CVE published
April 28, 2026
Record updated