CVE-2024-1478
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Summary
CVE-2024-1478 is a newly disclosed vulnerability affecting the Maintenance Mode plugin for WordPress. In versions up to 2.5.0, this plugin is susceptible to Sensitive Information Exposure via the REST API. Unauthenticated attackers can exploit this vulnerability to obtain post and page content, thereby bypassing the content protection provided by the plugin. This issue poses a significant risk as it allows unauthorized access to sensitive information, potentially leading to data breaches. WordPress users are strongly advised to update the plugin to the latest version as soon as possible to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.