Remote Code Execution Vulnerability in WP Maintenance Mode Plugin for WordPress
CVE-2018-20156
7.2HIGH
What is CVE-2018-20156?
The WP Maintenance Mode plugin prior to version 2.0.7 exposes a serious security flaw that allows remote authenticated site administrator users to execute arbitrary PHP code on a WordPress multisite network. This vulnerability enables an attacker with administrator access to manipulate the server environment, potentially leading to site takeover or further exploitation. It underscores the importance of maintaining updated plugin versions to mitigate security risks.