WP Clinic
Entrar Registrarse

SEGURIDAD DE PLUGINS

¿Es seguro Under Construction Page?

Vulnerabilidades conocidas, compatibilidad con PHP y alternativas más seguras para el plugin de WordPress Under Construction Page — verificado contra la base de datos de seguridad local de WP Clinic.

Qué hace este plugin

  • Slug: under-construction-page
  • 600000+ instalaciones activas

coming soon modecoming soon pageunder constructionunder construction modeunder construction page

Estado de mantenimiento

  • Última versión conocida: 5.81
  • Requiere PHP: 5.2+
  • PHP máximo soportado (analizado): 8.4

Vulnerabilidades conocidas

3 CVEs conocidos registrados para Under Construction Page. Reportadas entre 2021 y 2026.

CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2026-11426 Under Construction [under-construction-page] < 5.81 Limitación incorrecta de una ruta a un directorio restringido (Path Traversal) Media 6,5 < 5.81 5.81 2026-07-10 ✓ corregido en la última versión
Under Construction [under-construction-page] < 3.97 Desconocido < 3.97 3.97 2023-02-10 ✓ corregido en la última versión
CVE-2023-0832 Under Construction [under-construction-page] < 3.97 Falsificación de petición en sitios cruzados (CSRF) Media 4,3 < 3.97 3.97 2023-02-10 ✓ corregido en la última versión
CVE-2023-0831 Under Construction [under-construction-page] < 3.97 Falsificación de petición en sitios cruzados (CSRF) Media 4,3 < 3.97 3.97 2023-02-10 ✓ corregido en la última versión
Under Construction [under-construction-page] < 3.86 Desconocido < 3.86 3.86 2021-01-20 ✓ corregido en la última versión
Under Construction [under-construction-page] < 3.86 Desconocido < 3.86 3.86 2021-01-20 ✓ corregido en la última versión
Under Construction [under-construction-page] < 3.86 Desconocido < 3.86 3.86 ✓ corregido en la última versión

CVE-2026-11426

The UnderConstructionPage PRO plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 5.76. This is due to the plugin accepting arbitrary local file paths in the template_thumbnail parameter and copying their contents into a publicly accessible uploads file. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read arbitrary files on the server, which can contain sensitive information.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

Under Construction [under-construction-page] < 3.97

Update the WordPress Under Construction plugin to the latest available version (at least 3.97). An unknown person discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Under Construction Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. For example a password change which will then allow the malicious actor to login into the admin account. This vulnerability has been fixed in version 3.97.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2023-0832

The Under Construction plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.96. This is due to missing or incorrect nonce validation on the install_weglot function called via the admin_action_install_weglot action. This makes it possible for unauthenticated attackers to perform an unauthorized install of the Weglot Translate plugin via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2023-0831

The Under Construction plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.96. This is due to missing or incorrect nonce validation on the dismiss_notice function called via the admin_action_ucp_dismiss_notice action. This makes it possible for unauthenticated attackers to dismiss plugin notifications via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

Under Construction [under-construction-page] < 3.86

Authenticated Stored Cross-Site Scripting (XSS) vulnerability found by Julien (atmon3r) in WordPress Under Construction plugin (versions <= 3.85).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Under Construction [under-construction-page] < 3.86

The Under Construction plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 3.85, that make it possible for attackers with administrative privileges to inject arbitrary web scripts via the social and connect icon fields.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Under Construction [under-construction-page] < 3.86

The Underconstruction plugin admin configuration is vulnerable to stored XSS issues which will be triggered in the main page of the site, even when the unfiltered_html is disabled. Edit (WPScanTeam) A fix was attempted in v3.80, but was insufficient. In the meantime, more fields were found to be affected and the vendor was contacted with a detailed report to fix them.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Cómo solucionarlo

Mantén Under Construction Page actualizado — 5.81 es la última versión en wordpress.org, y cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en").

Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.

Alternativas más seguras / más establecidas

Verifica tu propio sitio WordPress

Ejecuta un escaneo pasivo gratis ahora, o crea una cuenta gratuita e instala el plugin de WP Clinic para un escaneo profundo de toda tu cuenta de hosting y reparación asistida por IA.