Vulnerabilities > Webfactoryltd > Minimal Coming Soon Maintenance Mode > 2.05

DATE CVE VULNERABILITY TITLE RISK
2024-02-05 CVE-2024-1075 Unspecified vulnerability in Webfactoryltd Minimal Coming Soon & Maintenance Mode
The Minimal Coming Soon – Coming Soon Page plugin for WordPress is vulnerable to maintenance mode bypass and information disclosure in all versions up to, and including, 2.37.
network
low complexity
webfactoryltd
5.3
2020-01-09 CVE-2020-6168 Incorrect Permission Assignment for Critical Resource vulnerability in Webfactoryltd Minimal Coming Soon & Maintenance Mode
A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows authenticated users with basic access to enable and disable maintenance-mode settings (impacting the availability and confidentiality of a vulnerable site, along with the integrity of the setting).
network
low complexity
webfactoryltd CWE-732
6.5
2020-01-09 CVE-2020-6166 Incorrect Default Permissions vulnerability in Webfactoryltd Minimal Coming Soon & Maintenance Mode
A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.15, allows authenticated users with basic access to export settings and change maintenance-mode themes.
network
low complexity
webfactoryltd CWE-276
5.5
2020-01-09 CVE-2020-6167 Cross-Site Request Forgery (CSRF) vulnerability in Webfactoryltd Minimal Coming Soon & Maintenance Mode
A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows a CSRF attack to enable maintenance mode, inject XSS, modify several important settings, or include remote files as a logo.
6.8