What the vulnerability does
01Description
Authentication Bypass by Spoofing vulnerability in helderk Maintenance Mode allows Functionality Bypass.This issue affects Maintenance Mode: from n/a through 3.0.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Authentication Bypass by Spoofing vulnerability in helderk Maintenance Mode allows Functionality Bypass.This issue affects Maintenance Mode: from n/a through 3.0.1.
Explanation of Vulnerability in Simple Terms
The Maintenance Mode plugin for WordPress contains an authentication bypass vulnerability. An attacker on the network can bypass authentication checks under specific conditions, gaining access to limited information. The vulnerability requires high attack complexity and results in low confidentiality impact. Update to a version newer than 3.0.1 to remediate.
What an attacker can do
Bypass authentication to access limited sensitive information on the site.
Potential impact on your site
Unauthorized users may access sensitive data despite maintenance mode protections being in place.
Conditions required to exploit
Network access; no user authentication required, but high attack complexity means specific conditions must be met.
Key dates
External resources
Related vulnerabilities