Smart Maintenance Mode
Smart Maintenance Mode has 4 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2025; 3 are fixed and 1 remains unpatched as of September 2026. Their average CVSS score is 4.8, and the most serious one scores 6.1 out of 10. 2025 was the busiest year with 3 disclosures.
The most common weakness is Cross-Site Scripting, behind 3 of the records (75%). Other recurring categories include Cross-Site Request Forgery (CSRF).
3 of the records (75%) have a vendor fix, while 1 remain unpatched. The oldest unresolved one dates back to 2024.
3 independent researchers contributed these findings, most of them (2) reported by Dogus Demirkiran. Smart Maintenance Mode is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.
CVE-2024-33638Smart Maintenance Mode <= 1.5.3 - Cross-Site Request Forgery
Read the full analysisVulnerability Records
Smart Maintenance Mode
Author
brijeshk89
Smart Maintenance Mode is a plugin which allows you to set your site to maintenance mode so that your readers see the Coming Soon page while you can see the actual development of your site. You can create ranges and define the IP range which will see the actual site using Smart Maintenance Mode. Features in Smart Maintenance Mode include: Enable/Disable Maintenance Mode Add/Remove Custom HTML content Add/Remove a Countdown to the time when your site will be live Add/Remove custom messages for Maintenance Mode page Add/Remove custom images for Maintenance Mode page Allow User roles to access actual site when Maintenance Mode is enabled Allow your IP to access actual site when Maintenance Mode is enabled Create IP ranges Delete IP ranges Enable/Disable IP ranges Completely FREE Licensed under GNU GPL version 3 Safe & Secure
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C