Description
WordPress Plugin WP Maintenance Mode & Site Under Construction is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently install arbitrary plugins. WordPress Plugin WP Maintenance Mode & Site Under Construction version 1.8.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.8.2 or latest
References
Related Vulnerabilities
WordPress Plugin Stallion WordPress SEO Cross-Site Scripting (2.0)
Oracle Application Server Other Vulnerability (CVE-2007-3861)
Apache read beyond bounds via ap_rwrite() Vulnerability (CVE-2022-28614)
WordPress Plugin Child Themes Helper Multiple Vulnerabilities (2.0)
Moodle Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2013-5674)