Junglewise Threat Intelligence

CVE-2022-50955: Leo Curtain WordPress plugin CSRF in maintenance mode toggle

CVE-2022-50955 · Severity: medium · CVSS 4.3 · Published 2026-05-10

Executive brief

The Curtain plugin for WordPress, which is used to manage site maintenance modes, contains a security flaw that allows unauthorized changes to a website's availability. An attacker can trick a site administrator into clicking a malicious link, which then automatically toggles the website's maintenance mode on or off. This could lead to unexpected site downtime or the premature exposure of a site that is still under development.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Curtain plugin for WordPress (version 1.0.2) due to a lack of proper nonce validation in the maintenance mode toggle functionality. The vulnerability is located in the options-general.php page when processing 'curtain' parameters. An attacker can exploit this by crafting a malicious request and tricking an authenticated administrator into executing it. Successful exploitation allows the attacker to programmatically enable or disable the site's maintenance mode. The plugin has been closed on the WordPress repository as of April 2022 due to this security issue, and users are advised to discontinue its use.

Affected products

  • Leo Curtain 1.0.2

Timeline

  • 2022-03-24: disclosed: Vulnerability discovered by researcher
  • 2022-03-30: other: Exploit published on Exploit-DB
  • 2022-04-27: other: Plugin closed on WordPress.org repository due to security issue
  • 2026-05-10: advisory: CVE published/updated via VulnCheck

References