The WP Maintenance Mode plugin before 2.0.7 for WordPress allows remote authenticated users to discover all subscriber e-mail addresses.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://www.wordfence.com/blog/2016/07/3-vulnerabilities-wp-maintenance-mode/ | third party advisory |