The Underconstruction Project maintains a narrowly scoped web application where the durable vulnerability signal centers on application-layer input-handling and request-validation issues, specifically cross-site scripting and cross-site request forgery. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Underconstruction Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-39320MEDIUM The underConstruction plugin <= 1.18 for WordPress echoes out the raw value of `$GLOBALS['PHP_SELF']` in the ucOptions.php file. On certain configurations including Apache+modPHP, | Sep 1, 2021 | 6.1 | 31 | NO | YES |
CVE-2013-2699MEDIUM Cross-site request forgery (CSRF) vulnerability in the underConstruction plugin before 1.09 for WordPress allows remote attackers to hijack the authentication of administrators for | Apr 10, 2014 | 6.8 | 18 | NO | NO |
CVE-2022-1896MEDIUM The underConstruction WordPress plugin before 1.21 does not sanitise or escape the "Display a custom page using your own HTML" setting before outputting it, allowing high privilege | Jun 20, 2022 | 4.8 | 16 | NO | NO |
CVE-2022-1895MEDIUM The underConstruction WordPress plugin before 1.20 does not have CSRF check in place when deactivating the construction mode, which could allow attackers to make a logged in admin | Jun 20, 2022 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Underconstruction Project.
Media articles that mention a CVE ID that affects a product developed by Underconstruction Project — matched by CVE ID, not by vendor name.