CVE-2024-0789
EUVD-2024-1657719.06.2024, 08:15
The WP Maintenance plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 6.1.9.2 due to insufficient IP address validation and use of user-supplied HTTP headers as a primary method for IP retrieval. This makes it possible for unauthenticated attackers to bypass maintenance mode.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| wp_maintenance_project | wp_maintenance | 𝑥 ≤ 6.1.9.2 | ADP |
Common Weakness Enumeration
References