Vulnerabilities > CVE-2020-6168 - Missing Authorization vulnerability in Webfactoryltd Minimal Coming Soon & Maintenance Mode

047910
CVSS 7.6 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
LOW
Integrity impact
LOW
Availability impact
HIGH
network
low complexity
webfactoryltd
CWE-862

Summary

A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows authenticated users with basic access to enable and disable maintenance-mode settings (impacting the availability and confidentiality of a vulnerable site, along with the integrity of the setting).

Vulnerable Configurations

Part Description Count
Application
Webfactoryltd
29

Common Weakness Enumeration (CWE)