PT-2025-43019 · WordPress · Ns Maintenance Mode For Wp

Khaled Alenazi

·

Published

2025-10-22

·

Updated

2025-10-22

·

CVE-2025-10638

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions NS Maintenance Mode for WP WordPress plugin versions through 1.3.1
Description The NS Maintenance Mode for WP WordPress plugin does not properly restrict access to its subscriber export function. This allows unauthenticated attackers to obtain a list of subscribers, including their names and email addresses. The affected function allows downloading a list of a site's subscribers.
Recommendations Update the NS Maintenance Mode for WP WordPress plugin to a version later than 1.3.1.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2025-10638

Affected Products

Ns Maintenance Mode For Wp