PT-2024-17266 · WordPress · Coming Soon

Lucio Sá

·

Published

2024-03-20

·

Updated

2024-03-20

·

CVE-2024-1181

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Coming Soon, Under Construction & Maintenance Mode By Dazzler plugin for WordPress versions up to, and including, 2.1.2
Description The issue arises from the plugin relying on the REQUEST URI to determine if the page being accessed is an admin area. This makes it possible for unauthenticated attackers to bypass maintenance mode and access the site, which may be considered confidential when in maintenance mode.
Recommendations For versions up to, and including, 2.1.2, update to a version later than 2.1.2 to resolve the issue. As a temporary workaround, consider restricting access to the admin area to minimize the risk of exploitation.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-1181

Affected Products

Coming Soon