CVE-2026-34896
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-34896 is a Cross-Site Request Forgery (CSRF) vulnerability in the Analytify "Under Construction, Coming Soon & Maintenance Mode" WordPress plugin. It affects all versions from the beginning through 2.1.1, and was disclosed and published on April 7, 2026, with a patch available in version 2.1.2. The vulnerability was discovered by security researcher Carlos Ferreira and reported to Patchstack on January 12, 2026. It carries a CVSS v3.1 base score of 7.5 (High) (Patchstack, GitHub Advisory).

Technical details

The vulnerability is classified as CWE-352 (Cross-Site Request Forgery), meaning the plugin fails to sufficiently verify whether requests were intentionally submitted by the authenticated user. An unauthenticated attacker can craft a malicious HTTP request or web page that, when visited or interacted with by a logged-in WordPress administrator, causes the administrator's browser to submit unauthorized requests to the plugin's administrative endpoints. Exploitation requires user interaction (an admin clicking a malicious link or visiting a crafted page) and has high attack complexity, but requires no privileges from the attacker (Patchstack, GitHub Advisory).

Impact

Successful exploitation allows an attacker to force a higher-privileged WordPress administrator to execute unwanted actions under their current authentication session, including unauthorized configuration changes to the plugin's maintenance mode, coming soon page settings, or other administrative functions. The potential impact spans high confidentiality, integrity, and availability consequences — including unauthorized access to sensitive plugin settings, manipulation of site-facing content (e.g., enabling or disabling maintenance mode), and potential disruption of site availability. The scope is limited to the affected WordPress installation but could be leveraged as part of a broader site compromise (Patchstack).

Exploitability

There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (GitHub Advisory). The EPSS score is approximately 0.018–0.021%, placing it in the 6th percentile for exploitation likelihood within the next 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack notes that vulnerabilities of this class are sometimes used in mass-exploit campaigns targeting WordPress sites at scale, regardless of site popularity (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the "Under Construction, Coming Soon & Maintenance Mode" plugin at version 2.1.1 or earlier, using tools like WPScan or Shodan.
  2. Craft malicious payload: Create an HTML page or link containing a hidden form or JavaScript that automatically submits a forged POST request to the vulnerable plugin's administrative action endpoint (e.g., a settings-update action), mimicking a legitimate admin request.
  3. Deliver to target: Trick a logged-in WordPress administrator into visiting the malicious page or clicking the crafted link via phishing email, social engineering, or a compromised third-party site.
  4. CSRF executes: The administrator's browser automatically sends the forged request with their valid session cookies, causing the plugin to process the unauthorized action (e.g., changing plugin configuration, disabling maintenance mode, or altering coming soon page content).
  5. Achieve objective: The attacker's desired configuration change is applied without the administrator's knowledge, potentially exposing the site or enabling further exploitation (Patchstack).

Indicators of compromise

  • Logs: WordPress access logs showing unexpected POST requests to plugin administrative endpoints (e.g., wp-admin/admin-post.php or wp-admin/options.php) from unusual referrer origins or with missing/invalid nonce values.
  • File System: Unexpected changes to plugin configuration stored in the WordPress database (wp_options table) related to the under-construction or maintenance mode plugin settings.
  • Logs: WordPress audit logs (if enabled via a security plugin) recording plugin settings changes at unusual times or from unexpected IP addresses without corresponding admin login activity.
  • Network: HTTP POST requests to WordPress admin endpoints originating from external or unexpected referrer domains, particularly those lacking a valid WordPress nonce token.

Mitigation and workarounds

The vendor has released version 2.1.2 of the "Under Construction, Coming Soon & Maintenance Mode" plugin, which patches this vulnerability. Administrators should update immediately to version 2.1.2 or later via the WordPress plugin dashboard. As interim measures, consider implementing additional CSRF protections via a web application firewall (WAF) or security plugin such as Patchstack, enforcing strong authentication for admin accounts, and reviewing plugin activity logs for suspicious configuration changes. Patchstack users can enable auto-update for vulnerable plugins to receive protection automatically (Patchstack).

Community reactions

The vulnerability was reported by independent researcher Carlos Ferreira through Patchstack's coordinated disclosure process and published on April 7, 2026. Patchstack classified it as low priority in terms of immediate exploitation risk, noting it is unlikely to be actively exploited in the near term. Brief social media mentions were observed on Mastodon and Bluesky shortly after disclosure, consistent with routine CVE announcement activity (Patchstack).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-16145HIGH7.2
  • gdpr-compliant-recaptcha-for-all-forms
NoYesAug 15, 2026
CVE-2026-18387MEDIUM6.5
  • groundhogg
NoYesAug 15, 2026
CVE-2026-16586MEDIUM6.5
  • contest-gallery
NoYesAug 15, 2026
CVE-2026-17090MEDIUM6.4
  • beaver-builder-lite-version
NoYesAug 15, 2026
CVE-2026-16146MEDIUM4.9
  • gdpr-compliant-recaptcha-for-all-forms
NoYesAug 15, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management