WP Secure Maintenance

WP Secure Maintenance has one disclosed vulnerability in the WordSec catalog, all reported in 2024; it is fixed as of September 2026. Their average CVSS score is 4.4, and the most serious one scores 4.4 out of 10.

The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).

The one issue recorded for WP Secure Maintenance has a vendor fix available, so running the current release closes it.

All of these findings were reported by Guido Iván García. WP Secure Maintenance is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.5.10.

Strategic Overview

Avg CVSSMedium
4.4/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all WP Secure Maintenance vulnerabilities before they are exploited.

Highest severity on recordCVSS 4.4CVE-2024-4753

WP Secure Maintenance <= 1.6 - Authenticated (Admin+) Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

1 records
WP Secure Maintenance banner
Latestv1.7

WP Secure Maintenance

Saad Iqbal

Author

Saad Iqbal

3.6(5)
72/100
Last Updated
2024-06-20 (2y ago)
Active Installs
1,000+
Downloads
58,236
Requires WP
5.2+
Requires PHP
7.0+
Tested up to
WP 6.5.10
Created
2016-03-02 (11y ago)

Want to lock your site for Maintenance or Development? Then this is the right Plugin. Using WP Secure Maintenance you can lock the whole site with a seceret PIN. Features: Set password to protect your site for maintenance or development Set your own logo or use default logo Change placeholder text for WP Secure Maintenance login form Change Submit button label for WP Secure Maintenance’s login form Change Error text for WP Secure Maintenance’s login form Docs & Support Will be available soon. If you are looking for WordPress Admin Security, use our Free WP SECURE ADMIN plugin. WP SECURE ADMIN Interested in contributing to WP Secure Maintenance Head over to the WP Secure Maintenance GitHub Repository to find out how you can pitch in 😉

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C