CVE-2024-0789
19.06.2024, 08:15
The WP Maintenance plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 6.1.9.2 due to insufficient IP address validation and use of user-supplied HTTP headers as a primary method for IP retrieval. This makes it possible for unauthenticated attackers to bypass maintenance mode.Enginsight
Vendor | Product | Version |
---|---|---|
wp_maintenance_project | wp_maintenance | 𝑥 ≤ 6.1.9.2 |
𝑥
= Vulnerable software versions
References