CVE-2020-35773

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
29/12/2020
Last modified:
17/07/2022

Description

The site-offline plugin before 1.4.4 for WordPress lacks certain wp_create_nonce and wp_verify_nonce calls, aka CSRF.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:freehtmldesigns:site_offline:*:*:*:*:*:wordpress:*:* 1.4.4 (excluding)