cleantalk
Vulnerabilities and Security Researches

Coming Soon Page & Maintenance Mode, fd9c668cc0f17388cd919046a5f290722fd40062

Published on
Jul 17, 2019
Research Description
Coming Soon Page &amp; Maintenance Mode [responsive-coming-soon] < 1.8.2 (closed) Coming Soon Page & Maintenance Mode <= 1.8.1 - Unauthenticated Settings Reset The Coming Soon Page & Maintenance Mode plugin for WordPress is vulnerable to unauthenticated settings reset in versions up to, and including 1.8.1 due to missing capability checks in the ~/functions/data-reset-post.php file which makes it possible for unauthenticated attackers to trigger a plugin settings reset.
Affected versions
Min -, max 1.8.2.
Status
vulnerable