CVE-2024-30480 LOW

CVE-2024-30480: WordPress CGC Maintenance Mode plugin <= 1.2 - IP Filtering Bypass vulnerability

Vendor Pippin Williamson
Product CGC Maintenance Mode
Weakness CWE-290
Published May 17, 2024
Last update April 28, 2026

CVSS base score

3.7/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

Authentication Bypass by Spoofing vulnerability in Pippin Williamson CGC Maintenance Mode allows Functionality Bypass.This issue affects CGC Maintenance Mode: from n/a through 1.2.

Explanation of Vulnerability in Simple Terms

02Summary

CGC Maintenance Mode through version 1.2 contains an authentication bypass vulnerability. An attacker on the network can access sensitive information by exploiting improper authentication checks, even without valid credentials. The vulnerability has low confidentiality impact and requires specific conditions to exploit. Site administrators should update to a version newer than 1.2.

What an attacker can do

03Attacker Capabilities

Access sensitive information without valid credentials by bypassing authentication checks.

Potential impact on your site

04Site Impact

Unauthorized users may view sensitive data if the plugin is active on your site.

Conditions required to exploit

05Prerequisites

Network access; specific conditions required (high attack complexity).

Key dates

06Disclosure timeline

May 17, 2024 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE