WP Maintenance Project maintains a WordPress maintenance plugin that, despite narrow scope, addresses a commonly managed administrative function across WordPress deployments, creating an input-handling surface exposed to both site administrators and web-based interfaces. The recurring vulnerability signal centers on cross-site scripting and cross-site request forgery issues, reflecting typical risks in WordPress plugin input validation and state-management patterns. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wp Maintenance Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-19979HIGH A flaw in the WordPress plugin, WP Maintenance before 5.0.6, allowed attackers to enable a vulnerable site's maintenance mode and inject malicious code affecting site visitors. The | Dec 26, 2019 | 8.8 | 26 | NO | NO |
CVE-2021-36828MEDIUM Authenticated (admin+) Stored Cross-Site Scripting (XSS) in WP Maintenance plugin <= 6.0.7 versions. | Apr 15, 2022 | 4.8 | 19 | NO | NO |
CVE-2022-30536MEDIUM Authenticated Stored Cross-Site Scripting (XSS) vulnerability in Florent Maillefaud's WP Maintenance plugin <= 6.0.7 at WordPress. | Jul 21, 2022 | 4.8 | 15 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wp Maintenance Project.
Media articles that mention a CVE ID that affects a product developed by Wp Maintenance Project — matched by CVE ID, not by vendor name.