Lucene search

K
cve[email protected]CVE-2024-1181
HistoryMar 20, 2024 - 7:15 a.m.

CVE-2024-1181

2024-03-2007:15:09
web.nvd.nist.gov
31
cve-2024-1181
dazzler
wordpress
plugin
maintenance mode
bypass
vulnerability

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

9.2 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.2%

The Coming Soon, Under Construction & Maintenance Mode By Dazzler plugin for WordPress is vulnerable to maintenance mode bypass in all versions up to, and including, 2.1.2. This is due to the plugin relying on the REQUEST_URI to determine if the page being accesses is an admin area. This makes it possible for unauthenticated attackers to bypass maintenance mode and access the site which may be considered confidential when in maintenance mode.

Affected configurations

Vulners
Node
dazzlersoftteam_members_showcaseRange2.1.2
VendorProductVersionCPE
dazzlersoftteam_members_showcase*cpe:2.3:a:dazzlersoft:team_members_showcase:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "dazzlersoft",
    "product": "Coming Soon, Under Construction & Maintenance Mode By Dazzler",
    "versions": [
      {
        "version": "*",
        "status": "affected",
        "lessThanOrEqual": "2.1.2",
        "versionType": "semver"
      }
    ],
    "defaultStatus": "unaffected"
  }
]

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

9.2 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.2%

Related for CVE-2024-1181