CVE-2020-35773: Freehtmldesigns Site Offline
High severity, CVSS 8.8. EPSS: 1% chance of exploitation in the next 30 days.
The site-offline plugin before 1.4.4 for WordPress lacks certain wp_create_nonce and wp_verify_nonce calls, aka CSRF.
Affected products
- Freehtmldesigns Site Offline: before 1.4.4 (fixed in 1.4.4)
Published 2020-12-29. Last modified 2026-06-17.