Known Vulnerabilities for products from Underconstruction Project
Listed below are 4 of the newest known vulnerabilities associated with the vendor "Underconstruction Project".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2022-1896 json | The underConstruction WordPress plugin before 1.21 does not sanitise or escape the "Display a custom page using your own HTML... | 4.8 - MEDIUM | 2022-06-20 | 2022-06-28 |
| CVE-2022-1895 json | The underConstruction WordPress plugin before 1.20 does not have CSRF check in place when deactivating the construction mode,... | 4.3 - MEDIUM | 2022-06-20 | 2022-06-28 |
| CVE-2021-39320 json | The underConstruction plugin <= 1.18 for WordPress echoes out the raw value of `$GLOBALS['PHP_SELF']` in the ucOptions.php fi... | 6.1 - MEDIUM | 2021-09-01 | 2021-09-08 |
| CVE-2013-2699 json | Cross-site request forgery (CSRF) vulnerability in the underConstruction plugin before 1.09 for WordPress allows remote attac... | Not Provided | 2014-04-10 | 2026-05-06 |