PT-2024-17266 · WordPress · Coming Soon
Lucio Sá
·
Published
2024-03-20
·
Updated
2024-03-20
·
CVE-2024-1181
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Coming Soon, Under Construction & Maintenance Mode By Dazzler plugin for WordPress versions up to, and including, 2.1.2
Description
The issue arises from the plugin relying on the REQUEST URI to determine if the page being accessed is an admin area. This makes it possible for unauthenticated attackers to bypass maintenance mode and access the site, which may be considered confidential when in maintenance mode.
Recommendations
For versions up to, and including, 2.1.2, update to a version later than 2.1.2 to resolve the issue.
As a temporary workaround, consider restricting access to the admin area to minimize the risk of exploitation.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Coming Soon