First published: Tue Feb 20 2024(Updated: )
The Coming Soon Maintenance Mode plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.5 via the REST API. This makes it possible for unauthenticated attackers to obtain post and page content thus bypassing the protection provided by the plugin.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
Awplife Coming Soon Maintenance Mode | <1.0.6 | |
WordPress Coming Soon, Maintenance Mode | <=1.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-1475 is considered a moderate severity vulnerability that allows unauthenticated attackers to access sensitive information.
To fix CVE-2024-1475, update the Coming Soon Maintenance Mode plugin to version 1.0.6 or higher.
Users of the Coming Soon Maintenance Mode plugin for WordPress versions up to 1.0.5 are affected by CVE-2024-1475.
CVE-2024-1475 is classified as a Sensitive Information Exposure vulnerability.
Yes, CVE-2024-1475 can be exploited remotely by unauthenticated attackers through the REST API.