DS Site Message
DS Site Message has one disclosed vulnerability in the WordSec catalog, all reported in 2024; it is fixed as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).
The one issue recorded for DS Site Message has a vendor fix available, so running the current release closes it.
All of these findings were reported by umi. DS Site Message is installed on roughly 10 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.7.7.
CVE-2024-34439DS Site Message <= 1.14.4 - Cross-Site Request Forgery
Read the full analysisVulnerability Records

DS Site Message
Author
Estian Hough
DS Site Message (DSSM) adds to WordPress a beautiful Maintenance, Coming Soon or Offline-Message page. Simply activate DSSM from the settings page in the administrator panel. Features Redirects non-admin website visitors to a maintenance or coming soon page. Displays a message to administrators when DSSM is enabled. Enable or disable temporarily unavailable headers. Includes a logo, title and message. Includes social media. Customizable text and background. Custom css. Live preview.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C