CVE-2024-1462

MEDIUM

Maintenance Page <1.0.8 - Info Disclosure

Title source: llm
STIX 2.1

Description

The Maintenance Page plugin for WordPress is vulnerable to Basic Information Exposure in all versions up to, and including, 1.0.8 via the REST API. This makes it possible for unauthenticated attackers to view post titles and content when the site is in maintenance mode.

Scores

CVSS v3 5.3
EPSS 0.0053
EPSS Percentile 40.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-284
Status published
Products (2)
themegrill/Maintenance Page < 1.0.8
themegrill/maintenance_page < 1.0.9
Published Mar 13, 2024
Tracked Since Feb 18, 2026