Maintenance Mode [hkdev-maintenance-mode] < 3.0.2
unknown
[en] Authentication Bypass by Spoofing vulnerability in helderk Maintenance Mode allows Functionality Bypass.This issue affects Maintenance Mode: from n/a through 3.0.1.
- Affected:
- up to 3.0.2
- Fixed in:
- 3.0.2
- Disclosed:
- May 17, 2024
CVE-2024-32708 on NVD →
Maintenance Mode by helderk <= 3.0.1 - Unauthenticated IP Spoofing
medium
The Maintenance Mode plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 3.0.1 due to insufficient IP address validation. This makes it possible for unauthenticated attackers to spoof their IP Address.
- CVSS:
- 5.3
- Affected:
- up to 3.0.1
- Fixed in:
- 3.0.2
- Disclosed:
- Apr 22, 2024
CVE-2024-32708 on NVD →
Maintenance Mode [hkdev-maintenance-mode] < 3.0.2
unknown
[en] The Maintenance Mode plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.5.0 via the REST API. This makes it possible for unauthenticated attackers to obtain post and page content via API thus bypassing the content protection provided by the plugin.
- Affected:
- up to 3.0.2
- Fixed in:
- 3.0.2
- Disclosed:
- Mar 5, 2024
CVE-2024-1478 on NVD →
Maintenance Mode <= 3.0.1 - Information Exposure
medium
The Maintenance Mode plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.1 via the REST API. This makes it possible for unauthenticated attackers to obtain post and page content via API thus bypassing the content protection provided by the plugin.
- CVSS:
- 5.3
- Affected:
- up to 3.0.1
- Fixed in:
- 3.0.2
- Disclosed:
- Mar 4, 2024
CVE-2024-1478 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database