CVE · Medium

CVE-2018-20154 — LightStart – Maintenance Mode, Coming Soon and Landing Page Builder [wp-maintenance-mode] < 2.0.7

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2018-20154 LightStart – Maintenance Mode, Coming Soon and Landing Page Builder [wp-maintenance-mode] < 2.0.7 Exposure of Sensitive Information to an Unauthorized Actor Medium 4.3 < 2.0.7 2.0.7 2016-07-06

CVE-2018-20154

The WP Maintenance Mode plugin versions prior to 2.0.7 contains a flaw that allows authenticated remote users to enumerate and access the email addresses of all subscribers on the WordPress installation.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.