Title: security vulnerability
Last modified: September 9, 2026

---

# security vulnerability

 *  Resolved [jimk1416](https://wordpress.org/support/users/jimk1416/)
 * (@jimk1416)
 * [3 weeks, 4 days ago](https://wordpress.org/support/topic/security-vulnerability-230/)
 * **Wordfence reported vulnerability**
 * Vulnerability Severity: 7.2/10.0 (High) [Vulnerability Information](https://www.wordfence.com/threat-intel/vulnerabilities/id/bf722bba-902b-44d3-bea4-b331ecacd579?source=plugin)
 * Unauthenticated Stored Cross-Site Scripting
   [https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/under-construction-page/under-construction-582-unauthenticated-stored-cross-site-scripting](https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/under-construction-page/under-construction-582-unauthenticated-stored-cross-site-scripting)

Viewing 6 replies - 1 through 6 (of 6 total)

 *  [danMWD](https://wordpress.org/support/users/danmwd/)
 * (@danmwd)
 * [3 weeks, 4 days ago](https://wordpress.org/support/topic/security-vulnerability-230/#post-19015805)
 * So what is being done about this?? 
   That does not look good – specially if you
   have the plugin installed on multiple sites! Is it still vulnerable if its switched
   on but still active? Where is version 5.8.2 let alone 5.8.3 – the log of versions
   says 5.8.1 as of right now (5.45pm GMT 9 September)? Can someone from the development
   team please advise?
 *  [danMWD](https://wordpress.org/support/users/danmwd/)
 * (@danmwd)
 * [3 weeks, 4 days ago](https://wordpress.org/support/topic/security-vulnerability-230/#post-19015810)
 * According to the other thread regarding this matter – it only effects the PRO
   version but its all very confusing – because Wordfence’s alert doesn’t seem to
   mention that it only effects the PRO version. Not nice!
 *  Thread Starter [jimk1416](https://wordpress.org/support/users/jimk1416/)
 * (@jimk1416)
 * [3 weeks, 4 days ago](https://wordpress.org/support/topic/security-vulnerability-230/#post-19015822)
 * The site that is giving me this vulnerability is a site NOT using the Pro version.
   It is running Ver 5.81.
   I think this is for the standard version not the Pro 
   version.
 *  Plugin Author [Alexandru Tapuleasa](https://wordpress.org/support/users/talextech/)
 * (@talextech)
 * [3 weeks, 4 days ago](https://wordpress.org/support/topic/security-vulnerability-230/#post-19015956)
 * It’s a false alert because both the free version and PRO version use the same
   slug. The issue is definitely only in the PRO version as it was related to the
   visual builder which does not exist in the free version.
 *  Thread Starter [jimk1416](https://wordpress.org/support/users/jimk1416/)
 * (@jimk1416)
 * [3 weeks, 4 days ago](https://wordpress.org/support/topic/security-vulnerability-230/#post-19015981)
 * OK thanks. The sites using the Pro version don’t have Wordfence so that explains
   why they’re not getting the notification. Not sure why the sites with the free
   version are seeing this then.
 *  Thread Starter [jimk1416](https://wordpress.org/support/users/jimk1416/)
 * (@jimk1416)
 * [3 weeks, 4 days ago](https://wordpress.org/support/topic/security-vulnerability-230/#post-19016537)
 * Ver 5.83 resolved the issue. Thanks

Viewing 6 replies - 1 through 6 (of 6 total)

You must be [logged in](https://login.wordpress.org/?redirect_to=https%3A%2F%2Fwordpress.org%2Fsupport%2Ftopic%2Fsecurity-vulnerability-230%2F%3Foutput_format%3Dmd&locale=en_US)
to reply to this topic.

 * ![](https://ps.w.org/under-construction-page/assets/icon-256x256.gif?rev=2284849)
 * [Under Construction](https://wordpress.org/plugins/under-construction-page/)
 * [Frequently Asked Questions](https://wordpress.org/plugins/under-construction-page/#faq)
 * [Support Threads](https://wordpress.org/support/plugin/under-construction-page/)
 * [Active Topics](https://wordpress.org/support/plugin/under-construction-page/active/)
 * [Unresolved Topics](https://wordpress.org/support/plugin/under-construction-page/unresolved/)
 * [Reviews](https://wordpress.org/support/plugin/under-construction-page/reviews/)

 * 7 replies
 * 3 participants
 * Last reply from: [jimk1416](https://wordpress.org/support/users/jimk1416/)
 * Last activity: [3 weeks, 4 days ago](https://wordpress.org/support/topic/security-vulnerability-230/#post-19016537)
 * Status: resolved