CVE-2024-43944 LOW

CVE-2024-43944: WordPress Maintenance & Coming Soon Redirect Animation plugin <= 2.3.3 - Bypass Vulnerability vulnerability

Vendor Ilyasine
Product Maintenance & Coming Soon Redirect Animation
Weakness CWE-290
Published August 29, 2024
Last update April 28, 2026

CVSS base score

3.7/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

Authentication Bypass by Spoofing vulnerability in ilyasine Maintenance & Coming Soon Redirect Animation maintenance-coming-soon-redirect-animation allows Identity Spoofing.This issue affects Maintenance & Coming Soon Redirect Animation: from n/a through <= 2.3.3.

Explanation of Vulnerability in Simple Terms

02Summary

The Maintenance & Coming Soon Redirect Animation plugin for WordPress contains an authentication bypass vulnerability in versions up to 2.3.3. An attacker on the network can access sensitive information without authentication by exploiting improper authentication checks. The vulnerability requires specific conditions to exploit but can expose confidential data. Update to a version newer than 2.3.3 to remediate.

What an attacker can do

03Attacker Capabilities

Access sensitive information without logging in by exploiting weak authentication checks.

Potential impact on your site

04Site Impact

Sensitive data may be exposed to unauthenticated visitors without your knowledge or action.

Conditions required to exploit

05Prerequisites

Network access; no authentication or user interaction required, but exploitation requires specific conditions.

Key dates

06Disclosure timeline

August 29, 2024 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE