Junglewise Threat Intelligence

CVE-2026-81295: Under Construction plugin unauthenticated cross-site scripting

CVE-2026-81295 · Severity: high · CVSS 7.1 · Published 2026-09-03

Executive brief

The Under Construction WordPress plugin, used to display maintenance/coming-soon pages on websites, contains an unauthenticated cross-site scripting (XSS) vulnerability. An attacker can inject malicious scripts that execute in the browsers of site visitors, potentially stealing visitor data, hijacking accounts, or redirecting users to malicious sites. The vulnerability affects versions up to 5.82 and is resolved in version 5.83.

Technical details

The vulnerability is a stored or reflected cross-site scripting (XSS) flaw in the Under Construction plugin (versions ≤ 5.82) that does not require authentication to exploit. An attacker can craft a malicious request or page containing JavaScript payload that, when processed by the plugin, is reflected back to site visitors or stored in the application. While user interaction is required (clicking a malicious link or visiting a crafted page), the low barrier to entry and high prevalence of the plugin make this a significant risk. Patch version 5.83 addresses the vulnerability; immediate upgrade is recommended.

Affected products

  • WebFactory Ltd Under Construction <=5.82

Timeline

  • 2026-09-02: disclosed
  • 2026-09-02: patched: Version 5.83 released
  • 2026-09-03: advisory

References