CVE-2020-35773: Freehtmldesigns Site Offline

High severity, CVSS 8.8. EPSS: 1% chance of exploitation in the next 30 days.

The site-offline plugin before 1.4.4 for WordPress lacks certain wp_create_nonce and wp_verify_nonce calls, aka CSRF.

Affected products

Published 2020-12-29. Last modified 2026-06-17.