CVE-2024-1476
Under Construction / Maintenance Mode from Acurax <= 2.6 - Information Exposure
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The Under Construction / Maintenance Mode from Acurax plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6 via the REST API. This makes it possible for unauthenticated attackers to obtain the contents of posts and pages when maintenance mode is active thus bypassing the protection provided by the plugin.
El modo En construcción/mantenimiento del complemento Acurax para WordPress es vulnerable a la exposición de información confidencial en todas las versiones hasta la 2.6 incluida, a través de la API REST. Esto hace posible que atacantes no autenticados obtengan el contenido de publicaciones y páginas cuando el modo de mantenimiento está activo, evitando así la protección proporcionada por el complemento.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2024-02-13 CVE Reserved
- 2024-02-27 CVE Published
- 2024-02-29 EPSS Updated
- 2024-08-09 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-284: Improper Access Control
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://wordpress.org/plugins/coming-soon-maintenance-mode-from-acurax | ||
https://www.wordfence.com/threat-intel/vulnerabilities/id/f28c47e6-a37d-4328-afb2-6a9e6b3fe20a?source=cve |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Acurax Search vendor "Acurax" | Under Construction / Maintenance Mode From Acurax Search vendor "Acurax" for product "Under Construction / Maintenance Mode From Acurax" | <= 2.6 Search vendor "Acurax" for product "Under Construction / Maintenance Mode From Acurax" and version " <= 2.6" | en |
Affected
|