CGC Maintenance Mode [cgc-maintenance-mode] <= 1.2 (unfixed + closed)
unknown
[en] Authentication Bypass by Spoofing vulnerability in Pippin Williamson CGC Maintenance Mode allows Functionality Bypass.This issue affects CGC Maintenance Mode: from n/a through 1.2.
- Affected:
- up to 1.2
- Fix:
- No patched version reported
- Disclosed:
- May 17, 2024
CVE-2024-30480 on NVD →
CGC Maintenance Mode [cgc-maintenance-mode] <= 1.2 (unfixed + closed)
unknown
[en] The CGC Maintenance Mode plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2 via the REST API. This makes it possible for unauthenticated attackers to view protected posts via REST API even when maintenance mode is enabled.
- Affected:
- up to 1.2
- Fix:
- No patched version reported
- Disclosed:
- Apr 4, 2024
CVE-2024-1418 on NVD →
CGC Maintenance Mode <= 1.2 - Sensitive Information Exposure
medium
The CGC Maintenance Mode plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2 via the REST API. This makes it possible for unauthenticated attackers to view protected posts via REST API even when maintenance mode is enabled.
- CVSS:
- 5.3
- Affected:
- up to 1.2
- Fix:
- No patched version reported
- Disclosed:
- Apr 3, 2024
CVE-2024-1418 on NVD →
CGC Maintenance Mode <= 1.2 - IP Spoofing
medium
The CGC Maintenance Mode plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 1.2 due to insufficient IP address validation. This makes it possible for unauthenticated attackers to spoof their IP address and bypass filtering.
- CVSS:
- 5.3
- Affected:
- up to 1.2
- Fix:
- No patched version reported
- Disclosed:
- Mar 28, 2024
CVE-2024-30480 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database