WordPress Plugin Vulnerabilities

Coming Soon Page & Maintenance Mode < 2.2.2 - Maintenance Mode Bypass

Description

The plugin is vulnerable to unauthorized access of data due to an improperly implemented URL check in the wpsm_coming_soon_redirect function, allowing unauthenticated attackers to view a site with maintenance mode or coming-soon mode enabled to view the site's content.

Affects Plugins

References

Classification

Type
NO AUTHORISATION
CWE

Miscellaneous

Original Researcher
Lucio Sá
Verified
No

Timeline

Publicly Published
2024-02-27 (about 2 months ago)
Added
2024-02-27 (about 2 months ago)
Last Updated
2024-03-11 (about 2 months ago)

Other