CVE-2024-1473: Coming Soon & Maintenance Mode by Colorlib <= 1.0.99 - Information Exposure
The Coming Soon & Maintenance Mode by Colorlib plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.0.99 via the REST API. This makes it possible for unauthenticated attackers to obtain post and page contents via REST API thus bypassing maintenance mode protection provided by the plugin.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1473?
CVE-2024-1473 has a medium severity rating due to its potential for information exposure.
How do I fix CVE-2024-1473?
To fix CVE-2024-1473, update the Coming Soon & Maintenance Mode plugin to version 1.0.100 or later.
Who is affected by CVE-2024-1473?
All users of the Coming Soon & Maintenance Mode by Colorlib plugin up to version 1.0.99 are affected by CVE-2024-1473.
What type of attack does CVE-2024-1473 allow?
CVE-2024-1473 allows unauthenticated attackers to access post and page contents via the REST API.
What does CVE-2024-1473 expose?
CVE-2024-1473 exposes information that could include sensitive content, thus bypassing maintenance mode.