Maintenance Switch
Maintenance Switch has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2023; 1 is fixed and 1 remains unpatched as of September 2026. Their average CVSS score is 5.8, and the most serious one scores 6.1 out of 10. 2023 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (50%). Other recurring categories include Cross-Site Scripting.
1 of the records (50%) have a vendor fix, while 1 remain unpatched. The oldest unresolved one dates back to 2023.
2 independent researchers contributed these findings, one record each. Maintenance Switch is installed on roughly 700 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2023-29235Maintenance Switch <= 1.5.2 - Cross-Site Request Forgery via 'admin_action_request'
Read the full analysisVulnerability Records

Maintenance Switch
Author
Fugu Design
One-click maintenance mode This plugin adds a button to the admin bar for toggling the builtin maintenance mode. Core maintenance mode A .maintenance file is generated and copied to the WordPress installation folder when turning on the maintenance mode. A maintenance.php file is generated and added to the wp-content folder for custom HTML code. Your custom maintenance page will also be active during the core, plugins and themes updates. Special Features set which roles can switch the maintenance mode set which roles can bypass the maintenance mode on the frontend set the entire HTML code used for the maintenance page preview the maintenance page before saving enable the theme file support, so you can create in each your themes a maintenance.php file to customize the maintenance page restore all default settings restore default HTML code create/delete the maintenance file in the active WP theme Translations English – default, always included French
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C