CVE-2026-34896 HIGH

CVE-2026-34896: WordPress Under Construction, Coming Soon & Maintenance Mode plugin <= 2.1.1 - Cross Site Request Forgery (CSRF) vulnerability

Vendor Analytify
Product Under Construction, Coming Soon & Maintenance Mode
Weakness CWE-352 · CSRF
Published April 7, 2026
Last update April 7, 2026

CVSS base score

7.5/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

Cross-Site Request Forgery (CSRF) vulnerability in Analytify Under Construction, Coming Soon & Maintenance Mode allows Cross Site Request Forgery.This issue affects Under Construction, Coming Soon & Maintenance Mode: from n/a through 2.1.1.

Explanation of Vulnerability in Simple Terms

02Summary

The Under Construction, Coming Soon & Maintenance Mode plugin for WordPress contains a cross-site request forgery (CSRF) vulnerability in versions up to 2.1.1. An attacker can trick a site administrator into performing unintended actions, such as changing plugin settings or disabling the maintenance mode, by crafting a malicious link or page. The vulnerability requires the admin to click the link while logged in.

What an attacker can do

03Attacker Capabilities

Trick a logged-in admin into changing plugin settings or disabling maintenance mode without their knowledge.

Potential impact on your site

04Site Impact

Your site's maintenance mode or plugin configuration could be altered by an attacker without your consent.

Conditions required to exploit

05Prerequisites

Admin must click a malicious link or visit an attacker-controlled page while logged into WordPress.

Key dates

06Disclosure timeline

April 7, 2026 CVE published
April 7, 2026 Record updated

Related vulnerabilities

08Related CVE