What the vulnerability does
01Description
Authentication Bypass by Spoofing vulnerability in WP Maintenance allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WP Maintenance: from n/a through 6.1.3.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Authentication Bypass by Spoofing vulnerability in WP Maintenance allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WP Maintenance: from n/a through 6.1.3.
Explanation of Vulnerability in Simple Terms
WP Maintenance versions up to 6.1.3 contain an authentication bypass vulnerability. An attacker can access sensitive information without proper credentials by exploiting a flaw in the authentication mechanism. The vulnerability requires specific network conditions to exploit but does not require user interaction. Site administrators should update to a version newer than 6.1.3.
What an attacker can do
Access sensitive information without authentication.
Potential impact on your site
Unauthorized users may view non-public data or configuration details from your WP Maintenance plugin.
Conditions required to exploit
Network access to the site; specific conditions must be met to trigger the vulnerability.
Key dates
External resources
Related vulnerabilities