PT-2024-16513 · WordPress · The Minimal Coming Soon – Coming Soon Page
Lucio Sá
·
Published
2024-02-05
·
Updated
2024-02-13
·
CVE-2024-1075
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
The Minimal Coming Soon – Coming Soon Page plugin for WordPress versions up to, and including, 2.37
Description
The issue is due to the plugin improperly validating the request path, making it possible for unauthenticated attackers to bypass maintenance mode and view pages that should be hidden. This results in maintenance mode bypass and information disclosure.
Recommendations
For versions up to, and including, 2.37, update to a version higher than 2.37 to resolve the issue. As a temporary workaround, consider restricting access to sensitive pages until a patch is available.
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
The Minimal Coming Soon – Coming Soon Page