Show filters
146 Total Results
Displaying 131-140 of 146
Sort by:
Attacker Value
Unknown

CVE-2020-6166

Disclosure Date: January 09, 2020 (last updated February 21, 2025)
A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.15, allows authenticated users with basic access to export settings and change maintenance-mode themes.
Attacker Value
Unknown

CVE-2020-6168

Disclosure Date: January 09, 2020 (last updated February 21, 2025)
A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows authenticated users with basic access to enable and disable maintenance-mode settings (impacting the availability and confidentiality of a vulnerable site, along with the integrity of the setting).
Attacker Value
Unknown

CVE-2020-6167

Disclosure Date: January 09, 2020 (last updated February 21, 2025)
A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows a CSRF attack to enable maintenance mode, inject XSS, modify several important settings, or include remote files as a logo.
Attacker Value
Unknown

CVE-2015-9429

Disclosure Date: September 26, 2019 (last updated November 27, 2024)
The yith-maintenance-mode plugin before 1.2.0 for WordPress has CSRF with resultant XSS via the wp-admin/themes.php?page=yith-maintenance-mode panel_page parameter.
Attacker Value
Unknown

CVE-2019-5394

Disclosure Date: June 05, 2019 (last updated November 27, 2024)
The HPE Nonstop Maintenance Entity family of products are vulnerable to local disclosure of information, such as system layout and configuration.
0
Attacker Value
Unknown

CVE-2019-19979

Disclosure Date: February 28, 2019 (last updated November 27, 2024)
A flaw in the WordPress plugin, WP Maintenance before 5.0.6, allowed attackers to enable a vulnerable site's maintenance mode and inject malicious code affecting site visitors. There was CSRF with resultant XSS.
Attacker Value
Unknown

CVE-2018-20155

Disclosure Date: December 14, 2018 (last updated November 27, 2024)
The WP Maintenance Mode plugin before 2.0.7 for WordPress allows remote authenticated subscriber users to bypass intended access restrictions on changes to plugin settings.
0
Attacker Value
Unknown

CVE-2018-20156

Disclosure Date: December 14, 2018 (last updated November 27, 2024)
The WP Maintenance Mode plugin before 2.0.7 for WordPress allows remote authenticated "site administrator" users to execute arbitrary PHP code throughout a multisite network.
0
Attacker Value
Unknown

CVE-2018-20154

Disclosure Date: December 14, 2018 (last updated November 27, 2024)
The WP Maintenance Mode plugin before 2.0.7 for WordPress allows remote authenticated users to discover all subscriber e-mail addresses.
0
Attacker Value
Unknown

CVE-2018-14722

Disclosure Date: August 15, 2018 (last updated November 27, 2024)
An issue was discovered in evaluate_auto_mountpoint in btrfsmaintenance-functions in btrfsmaintenance through 0.4.1. Code execution as root can occur via a specially crafted filesystem label if btrfs-{scrub,balance,trim} are set to auto in /etc/sysconfig/btrfsmaintenance (this is not the default, though).
0