CVE-2024-1370CVSS 5.3CMS
CVE-2024-1370: maintenance page vulnerability
The Maintenance Page plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the subscribe_download function hooked via AJAX action in all versions up to, and including, 1.0.8. This makes it possible for authenticated attackers, with subscriber access or higher, to download a csv containing subscriber emails.
- CVSS
- 5.3 MEDIUM
- EPSS
- 36.39%
- Known exploited
- not in KEV
- Product
- maintenance page
What is known
The Maintenance Page plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the subscribe_download function hooked via AJAX action in all versions up to, and including, 1.0.8. This makes it possible for authenticated attackers, with subscriber access or higher, to download a csv containing subscriber emails.