5.3
CVE-2024-1075
- EPSS 0.48%
- Veröffentlicht 05.02.2024 22:16:07
- Zuletzt bearbeitet 21.11.2024 08:49:44
- Quelle security@wordfence.com
- CVE-Watchlists
- Unerledigt
Minimal Coming Soon – Coming Soon Page <= 2.37 - Unauthenticated Maintenance Mode Bypass
The Minimal Coming Soon – Coming Soon Page plugin for WordPress is vulnerable to maintenance mode bypass and information disclosure in all versions up to, and including, 2.37. This is due to the plugin improperly validating the request path. This makes it possible for unauthenticated attackers to bypass maintenance mode and view pages that should be hidden.
Mögliche Gegenmaßnahme
Minimal Coming Soon – Coming Soon Page: Update to version 2.38, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Minimal Coming Soon – Coming Soon Page
Version
* - 2.37
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Webfactoryltd ≫ Minimal Coming Soon & Maintenance Mode SwPlatformwordpress Version <= 2.37
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.48% | 0.643 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
| security@wordfence.com | 3.7 | 2.2 | 1.4 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
|