WP Maintenance Mode <= 2.0.6 - Missing Authorization

2016-07-06 00:00
Sean Murphy

Vulnerability Overview

The WP Maintenance Mode plugin before 2.0.7 for WordPress allows remote authenticated subscriber users to bypass intended access restrictions on changes to plugin settings.

Technical Analysis

REMEDIATION: Update to version 2.0.7, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C