YITH Maintenance Mode

YITH Maintenance Mode has 3 disclosed vulnerabilities in the WordSec catalog, reported between 2015 and 2021; all 3 are fixed as of September 2026. Their average CVSS score is 6.6, and the most serious one scores 6.9 out of 10. 2021 was the busiest year with 2 disclosures.

The most common weakness is Cross-Site Scripting, behind 3 of the records (100%).

Every one of the 3 issues recorded for YITH Maintenance Mode has a vendor fix available, so running the current release closes all known holes.

3 independent researchers contributed these findings, one record each. YITH Maintenance Mode is installed on roughly 5,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.

Strategic Overview

Avg CVSSMedium
6.6/ 10
Patch Coverage100%
Open

0

Fixed

3

Get automatic notifications for all YITH Maintenance Mode vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.9CVE-2021-36845

YITH Maintenance Mode <= 1.3.8 - Multiple Authenticated Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

3 records
YITH Maintenance Mode banner
Latestv1.10.4

YITH Maintenance Mode

YITHEMES

Author

YITHEMES

4.1(27)
82/100
Last Updated
2025-04-24 (1y ago)
Active Installs
5,000+
Downloads
305,597
Requires WP
6.4+
Requires PHP
7.4+
Tested up to
WP 6.8.8
Created
2013-05-30 (14y ago)

If you’re working on your website and would like to make it known to your visitors, install the plugin YITH Maintenance Mode to quickly set a lovely customizable page to let your visitors know the site is closed for maintenance. A working demo is available here. Full documentation is available here. This plugin is 100% compatible with WPML Installation Once you have installed the plugin, you just need to activate the plugin in order to enable it. Configuration YITH Maintenance Mode will add a new page under Appearance -> Maintenance Mode, where you can configure the plugin and customize the frontend page. GDPR Disclaimer As you can see in Google FAQ: The Google Fonts API is designed to limit the collection, storage, and use of end-user data to what is needed to serve fonts efficiently. […] Google Fonts logs records of the CSS and the font file requests, and access to this data is kept secure. […] We use data from Google’s web crawler to detect which websites use Google fonts. In other words, when someone visits your website, Google will be able to access the IP address they used to access it. As a result of using Google Fonts, you implicitly accept their terms and conditions, and you must inform people visiting your site of this in accordance with the current GDPR law in Europe. Developer Are you a developer? Want to customize the templates or the style of the plugin? Read on the documentation and discover how to do that. Suggestions If you have suggestions about how to improve YITH Maintenance Mode, you can write us so we can bundle them into YITH Maintenance Mode. Translators Available Languages English (Default) Dutch Italian Spanish If you have created your own language pack, or have an update for an existing one, you can send gettext PO and MO file use so we can bundle it into YITH Maintenance Mode Languages. Documentation Full documentation is available here.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C