PT-2025-43019 · WordPress · Ns Maintenance Mode For Wp
Khaled Alenazi
·
Published
2025-10-22
·
Updated
2025-10-22
·
CVE-2025-10638
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
NS Maintenance Mode for WP WordPress plugin versions through 1.3.1
Description
The NS Maintenance Mode for WP WordPress plugin does not properly restrict access to its subscriber export function. This allows unauthenticated attackers to obtain a list of subscribers, including their names and email addresses. The affected function allows downloading a list of a site's subscribers.
Recommendations
Update the NS Maintenance Mode for WP WordPress plugin to a version later than 1.3.1.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ns Maintenance Mode For Wp