Vulnerabilities > CVE-2019-25139 - Missing Authorization vulnerability in Wpshopmart Coming Soon Page & Maintenance Mode

047910
CVSS 5.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
LOW
Availability impact
NONE
network
low complexity
wpshopmart
CWE-862

Summary

The Coming Soon Page & Maintenance Mode plugin for WordPress is vulnerable to unauthenticated settings reset in versions up to, and including 1.8.1 due to missing capability checks in the ~/functions/data-reset-post.php file which makes it possible for unauthenticated attackers to trigger a plugin settings reset.

Vulnerable Configurations

Part Description Count
Application
Wpshopmart
58

Common Weakness Enumeration (CWE)