Information Disclosure in WP Maintenance Mode Plugin for WordPress
CVE-2018-20154
4.3MEDIUM
What is CVE-2018-20154?
The WP Maintenance Mode plugin prior to version 2.0.7 for WordPress contains a security flaw that enables remote authenticated users to access and enumerate all subscriber email addresses. This vulnerability poses a risk of exposing sensitive information, allowing for potential phishing or other malicious activities targeting affected users.