PLUGIN SECURITY
Is Wp Maintenance Mode safe?
Easy Drag & Drop Page Builder that adds a splash page to your site that it's perfect for a coming soon page, maintenance or landing page.
What this plugin does
- Slug:
wp-maintenance-mode - Author: Themeisle
- 400000+ active installs
- 86/100 rating (873 reviews on wordpress.org)
- 20134910 all-time downloads
- On WordPress.org since 2010-02-26
coming soonlanding pagemaintenance modesplash pageunder construction
Maintenance status
- Latest known version: 2.6.23
- Last updated: 2026-08-20 6:45pm GMT
- Tested up to WordPress: 7.1
- Requires PHP: 7.1+
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
6 known CVEs on file for Wp Maintenance Mode. Reported between 2013 and 2024.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2023-7019 | LightStart – Maintenance Mode, Coming Soon and Landing Page Builder [wp-maintenance-mode] < 2.6.9 | Missing Authorization | Medium 4.3 | < 2.6.9 | 2.6.9 | 2024-01-05 | ✓ fixed in latest |
| CVE-2022-1576 | LightStart – Maintenance Mode, Coming Soon and Landing Page Builder [wp-maintenance-mode] < 2.4.5 | Cross-Site Request Forgery (CSRF) | Medium 6.5 | < 2.4.5 | 2.4.5 | 2022-06-20 | ✓ fixed in latest |
| CVE-2018-20156 | LightStart – Maintenance Mode, Coming Soon and Landing Page Builder [wp-maintenance-mode] < 2.0.7 | Improper Input Validation | High 7.2 | < 2.0.7 | 2.0.7 | 2018-12-14 | ✓ fixed in latest |
| CVE-2018-20155 | LightStart – Maintenance Mode, Coming Soon and Landing Page Builder [wp-maintenance-mode] < 2.0.7 | Missing Authorization | Medium 4.3 | < 2.0.7 | 2.0.7 | 2016-07-06 | ✓ fixed in latest |
| CVE-2018-20154 | LightStart – Maintenance Mode, Coming Soon and Landing Page Builder [wp-maintenance-mode] < 2.0.7 | Exposure of Sensitive Information to an Unauthorized Actor | Medium 4.3 | < 2.0.7 | 2.0.7 | 2016-07-06 | ✓ fixed in latest |
| CVE-2013-3250 | LightStart – Maintenance Mode, Coming Soon and Landing Page Builder [wp-maintenance-mode] < 1.8.8 | Cross-Site Request Forgery (CSRF) | Unknown | < 1.8.8 | 1.8.8 | 2013-04-22 | ✓ fixed in latest |
How to fix it
Keep Wp Maintenance Mode updated — 2.6.23 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- Elementor Website Builder – more than just a page builder — 10000000+ active installs — 90/100 (7297)
- Maintenance — 1000000+ active installs — 88/100 (860) — max PHP 8.4
- Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode — 700000+ active installs — 98/100 (4699) — max PHP <8.0
- Page Builder: Pagelayer – Drag and Drop website builder — 400000+ active installs — 78/100 (102) — max PHP 8.4
- Templately – Elementor & Gutenberg Template Library: 6500+ Free & Pro Ready Templates And Cloud! — 300000+ active installs — 100/100 (382)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.