Beta

Report

Coming Soon, Under Construction & Maintenance Mode By Dazzler <= 2.1.2 is vulnerable to Maintenance Mode Bypass vulnerability

Unauthenticated
Published
2024-03-19

The Coming Soon, Under Construction & Maintenance Mode By Dazzler plugin for WordPress is vulnerable to maintenance mode bypass in all versions up to, and including, 2.1.2. This is due to the plugin relying on the REQUEST_URI to determine if the page being accesses is an admin area. This makes it possible for unauthenticated attackers to bypass maintenance mode and access the site which may be considered confidential when in maintenance mode.

CVSS

Score:5.3

Severity:Medium

Version: 2.1.2

There is a patch available in v2.1.3 and we strongly recommend you update to this version as soon as possible.