WP Maintenance
WP Maintenance has 7 disclosed vulnerabilities in the WordSec catalog, reported between 2019 and 2025; all 7 are fixed as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 2 high. 2024 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Scripting, behind 2 of the records (29%). Other recurring categories include Use Of Less Trusted Source, Cross-Site Request Forgery (CSRF).
Every one of the 7 issues recorded for WP Maintenance has a vendor fix available, so running the current release closes all known holes.
7 independent researchers contributed these findings, one record each. WP Maintenance is installed on roughly 50,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 0.
CVE-2019-19979WP Maintenance <= 5.0.5 - Cross-Site Request Forgery to Stored Cross-Site Scripting
Read the full analysisVulnerability Records

WP Maintenance
Author
Florent Maillefaud
The WP Maintenance plugin allows you to put your website on the waiting time for you to do maintenance or launch your website. Personalize this page, pictures and countdown with: Features Choice texts colors and fonts Upload logo picture Upload background picture or pattern Countdown Custom Code Header for Analytics ready Social Networks ready Customize CSS Insert for shorcode (Newletter or Contact form) Enable “503 Service temporarily unavailable” Choose access by Roles and Capabilities Choose access by ID Pages Choose access by IP addresses wp-maintenance.pot file available
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C