DS Site Message

DS Site Message has one disclosed vulnerability in the WordSec catalog, all reported in 2024; it is fixed as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).

The one issue recorded for DS Site Message has a vendor fix available, so running the current release closes it.

All of these findings were reported by umi. DS Site Message is installed on roughly 10 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.7.7.

Strategic Overview

Avg CVSSMedium
4.3/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all DS Site Message vulnerabilities before they are exploited.

Highest severity on recordCVSS 4.3CVE-2024-34439

DS Site Message <= 1.14.4 - Cross-Site Request Forgery

Read the full analysis

Vulnerability Records

1 records
Showing 1–1 of 1 reports
DS Site Message banner
Latestv1.14.5

DS Site Message

Estian Hough

Author

Estian Hough

0.0(0)
0/100
Last Updated
2025-02-25 (2y ago)
Active Installs
10+
Downloads
12,714
Requires WP
4.9.4+
Requires PHP
7.2+
Tested up to
WP 6.7.7
Created
2018-02-21 (9y ago)

DS Site Message (DSSM) adds to WordPress a beautiful Maintenance, Coming Soon or Offline-Message page. Simply activate DSSM from the settings page in the administrator panel. Features Redirects non-admin website visitors to a maintenance or coming soon page. Displays a message to administrators when DSSM is enabled. Enable or disable temporarily unavailable headers. Includes a logo, title and message. Includes social media. Customizable text and background. Custom css. Live preview.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C