VendorsDesignmodowp_maintenance_modeany version
Vulnerabilities

Designmodo WP Maintenance Mode any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2018-20156
The WP Maintenance Mode plugin before 2.0.7 for WordPress allows remote authenticated "site administrator" users to execute arbitrary PHP code throughout a multisite network.
Published 2018-12-14 · Modified
7.2EPSS 0.015
CVE-2018-20154
The WP Maintenance Mode plugin before 2.0.7 for WordPress allows remote authenticated users to discover all subscriber e-mail addresses.
Published 2018-12-14 · Modified
4.3EPSS 0.010
CVE-2018-20155
The WP Maintenance Mode plugin before 2.0.7 for WordPress allows remote authenticated subscriber users to bypass intended access restrictions on changes to plugin settings.
Published 2018-12-14 · Modified
4.3EPSS 0.008