CVE-2024-1462

The Maintenance Page plugin for WordPress is vulnerable to Basic Information Exposure in all versions up to, and including, 1.0.8 via the REST API. This makes it possible for unauthenticated attackers to view post titles and content when the site is in maintenance mode.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

cpe:2.3:a:themegrill:maintenance_page:*:*:*:*:*:wordpress:*:*

History

24 Feb 2025, 14:59

Type Values Removed Values Added
CWE NVD-CWE-noinfo
First Time Themegrill maintenance Page
Themegrill
CPE cpe:2.3:a:themegrill:maintenance_page:*:*:*:*:*:wordpress:*:*
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/653bf021-370d-4787-9ded-c5c915aed1d6?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/653bf021-370d-4787-9ded-c5c915aed1d6?source=cve - Third Party Advisory
References () https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3037664%40maintenance-page%2Ftrunk&old=1218033%40maintenance-page%2Ftrunk&sfp_email=&sfph_mail= - () https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3037664%40maintenance-page%2Ftrunk&old=1218033%40maintenance-page%2Ftrunk&sfp_email=&sfph_mail= - Patch

13 Mar 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-13 16:15

Updated : 2025-02-24 14:59


NVD link : CVE-2024-1462

Mitre link : CVE-2024-1462


JSON object : View

Products Affected

themegrill

  • maintenance_page