Описание
A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows authenticated users with basic access to enable and disable maintenance-mode settings (impacting the availability and confidentiality of a vulnerable site, along with the integrity of the setting).
Ссылки
- Release NotesVendor Advisory
- Third Party Advisory
- ExploitThird Party Advisory
- Release NotesVendor Advisory
- Third Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.10 (включая)
cpe:2.3:a:webfactoryltd:minimal_coming_soon_\&_maintenance_mode:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 79%
0.01239
Низкий
7.6 High
CVSS3
7.6 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-862
Связанные уязвимости
github
больше 3 лет назад
A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows authenticated users with basic access to enable and disable maintenance-mode settings (impacting the availability and confidentiality of a vulnerable site, along with the integrity of the setting).
EPSS
Процентиль: 79%
0.01239
Низкий
7.6 High
CVSS3
7.6 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-862