Vulnerability Description
The Coming Soon Page & Maintenance Mode plugin for WordPress is vulnerable to unauthorized access of data due to an improperly implemented URL check in the wpsm_coming_soon_redirect function in all versions up to, and including, 2.2.1. This makes it possible for unauthenticated attackers to view a site with maintenance mode or coming-soon mode enabled to view the site's content.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Wpshopmart | Coming Soon Page \& Maintenance Mode | < 2.2.2 |
Related Weaknesses (CWE)
References
- https://plugins.trac.wordpress.org/browser/responsive-coming-soon/trunk/redirectPatch
- https://www.wordfence.com/threat-intel/vulnerabilities/id/e3c52d6e-b3f4-4ba8-aeeThird Party Advisory
- https://plugins.trac.wordpress.org/browser/responsive-coming-soon/trunk/redirectPatch
- https://www.wordfence.com/threat-intel/vulnerabilities/id/e3c52d6e-b3f4-4ba8-aeeThird Party Advisory
FAQ
What is CVE-2024-1136?
CVE-2024-1136 is a vulnerability with a CVSS score of 5.3 (MEDIUM). The Coming Soon Page & Maintenance Mode plugin for WordPress is vulnerable to unauthorized access of data due to an improperly implemented URL check in the wpsm_coming_soon_redirect function in all ve...
How severe is CVE-2024-1136?
CVE-2024-1136 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-1136?
Check the references section above for vendor advisories and patch information. Affected products include: Wpshopmart Coming Soon Page \& Maintenance Mode.