What the vulnerability does
01Description
Authentication Bypass by Spoofing vulnerability in Filipe Seabra WordPress Manutenção allows Functionality Bypass.This issue affects WordPress Manutenção: from n/a through 1.0.6.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Authentication Bypass by Spoofing vulnerability in Filipe Seabra WordPress Manutenção allows Functionality Bypass.This issue affects WordPress Manutenção: from n/a through 1.0.6.
Explanation of Vulnerability in Simple Terms
WordPress Manutenção plugin versions up to 1.0.6 contain an authentication bypass vulnerability. An attacker on the network can access sensitive information without valid credentials by exploiting improper authentication checks. The vulnerability has low confidentiality impact and requires specific conditions to exploit. Update to a version newer than 1.0.6 to remediate.
What an attacker can do
Read sensitive information without providing valid login credentials.
Potential impact on your site
Unauthorized users may access non-public data exposed by the plugin without logging in.
Conditions required to exploit
Network access to the site; no user interaction or authentication required.
Key dates
External resources
Related vulnerabilities