What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in Analytify Under Construction, Coming Soon & Maintenance Mode allows Cross Site Request Forgery.This issue affects Under Construction, Coming Soon & Maintenance Mode: from n/a through 2.1.1.
Explanation of Vulnerability in Simple Terms
02Summary
The Under Construction, Coming Soon & Maintenance Mode plugin for WordPress contains a cross-site request forgery (CSRF) vulnerability in versions up to 2.1.1. An attacker can trick a site administrator into performing unintended actions, such as changing plugin settings or disabling the maintenance mode, by crafting a malicious link or page. The vulnerability requires the admin to click the link while logged in.
What an attacker can do
03Attacker Capabilities
Trick a logged-in admin into changing plugin settings or disabling maintenance mode without their knowledge.
Potential impact on your site
04Site Impact
Your site's maintenance mode or plugin configuration could be altered by an attacker without your consent.
Conditions required to exploit
05Prerequisites
Admin must click a malicious link or visit an attacker-controlled page while logged into WordPress.
Key dates
06Disclosure timeline
April 7, 2026
CVE published
April 7, 2026
Record updated