
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34896 is a Cross-Site Request Forgery (CSRF) vulnerability in the Analytify "Under Construction, Coming Soon & Maintenance Mode" WordPress plugin. It affects all versions from the beginning through 2.1.1, and was disclosed and published on April 7, 2026, with a patch available in version 2.1.2. The vulnerability was discovered by security researcher Carlos Ferreira and reported to Patchstack on January 12, 2026. It carries a CVSS v3.1 base score of 7.5 (High) (Patchstack, GitHub Advisory).
The vulnerability is classified as CWE-352 (Cross-Site Request Forgery), meaning the plugin fails to sufficiently verify whether requests were intentionally submitted by the authenticated user. An unauthenticated attacker can craft a malicious HTTP request or web page that, when visited or interacted with by a logged-in WordPress administrator, causes the administrator's browser to submit unauthorized requests to the plugin's administrative endpoints. Exploitation requires user interaction (an admin clicking a malicious link or visiting a crafted page) and has high attack complexity, but requires no privileges from the attacker (Patchstack, GitHub Advisory).
Successful exploitation allows an attacker to force a higher-privileged WordPress administrator to execute unwanted actions under their current authentication session, including unauthorized configuration changes to the plugin's maintenance mode, coming soon page settings, or other administrative functions. The potential impact spans high confidentiality, integrity, and availability consequences — including unauthorized access to sensitive plugin settings, manipulation of site-facing content (e.g., enabling or disabling maintenance mode), and potential disruption of site availability. The scope is limited to the affected WordPress installation but could be leveraged as part of a broader site compromise (Patchstack).
There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (GitHub Advisory). The EPSS score is approximately 0.018–0.021%, placing it in the 6th percentile for exploitation likelihood within the next 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack notes that vulnerabilities of this class are sometimes used in mass-exploit campaigns targeting WordPress sites at scale, regardless of site popularity (Patchstack).
wp-admin/admin-post.php or wp-admin/options.php) from unusual referrer origins or with missing/invalid nonce values.wp_options table) related to the under-construction or maintenance mode plugin settings.The vendor has released version 2.1.2 of the "Under Construction, Coming Soon & Maintenance Mode" plugin, which patches this vulnerability. Administrators should update immediately to version 2.1.2 or later via the WordPress plugin dashboard. As interim measures, consider implementing additional CSRF protections via a web application firewall (WAF) or security plugin such as Patchstack, enforcing strong authentication for admin accounts, and reviewing plugin activity logs for suspicious configuration changes. Patchstack users can enable auto-update for vulnerable plugins to receive protection automatically (Patchstack).
The vulnerability was reported by independent researcher Carlos Ferreira through Patchstack's coordinated disclosure process and published on April 7, 2026. Patchstack classified it as low priority in terms of immediate exploitation risk, noting it is unlikely to be actively exploited in the near term. Brief social media mentions were observed on Mastodon and Bluesky shortly after disclosure, consistent with routine CVE announcement activity (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."