Conditionnal Maintenance Mode for WordPress
Conditionnal Maintenance Mode for WordPress has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).
The one issue recorded for Conditionnal Maintenance Mode for WordPress has a vendor fix available, so running the current release closes it.
All of these findings were reported by dayea song. The current release is tested up to WordPress 6.7.7.
CVE-2025-12586Conditional Maintenance Mode for WordPress <= 1.0.0 - Cross-Site Request Forgery
Read the full analysisVulnerability Records

Conditionnal Maintenance Mode for WordPress
Author
Walid Sadfi
The Conditionnal Maintenance Mode for WordPress plugin allows the administrator to enable or disable maintenance mode for selected user roles. The administrator can also customize the maintenance message that will be displayed to users who do not have the necessary roles. This plugin is useful when you are performing updates or maintenance on your website and want to limit access to certain users while you work.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C