CVE-2020-6166
MEDIUM EXPLOITEDWordPress Minimal Coming Soon & Maintenance Mode <2.15 - Info Discl...
Title source: llmExploitation Summary
CVE-2020-6166 has been observed exploited in the wild (reported by VulnCheck KEV).
Description
A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.15, allows authenticated users with basic access to export settings and change maintenance-mode themes.
References (3)
Core 3
Core References
Third Party Advisory x_refsource_misc
https://wpvulndb.com/vulnerabilities/10009
Release Notes, Vendor Advisory x_refsource_confirm
https://wordpress.org/plugins/minimal-coming-soon-maintenance-mode/#developers
Exploit, Third Party Advisory x_refsource_misc
https://www.wordfence.com/blog/2020/01/multiple-vulnerabilities-patched-in-minimal-coming-soon-maintenance-mode-coming-soon-page-plugin/
Scores
CVSS v3
5.4
EPSS
0.0107
EPSS Percentile
60.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Details
VulnCheck KEV
2020-01-08
CWE
CWE-276
Status
published
Products (1)
webfactoryltd/minimal_coming_soon_\&_maintenance_mode
< 2.15
Published
Jan 09, 2020
Tracked Since
Feb 18, 2026