The Easy Maintenance Mode plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.2 via the REST API. This makes it possible for authenticated attackers to obtain post and page content via REST API thus bypassign the protection provided by the plugin.
History

Wed, 25 Feb 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Mukeshpanchal
Mukeshpanchal easy Maintenance Mode
CPEs cpe:2.3:a:mukeshpanchal:easy_maintenance_mode:*:*:*:*:*:*:*:*
Vendors & Products Mukeshpanchal
Mukeshpanchal easy Maintenance Mode
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2024-08-05T19:31:59.559Z

Reserved: 2024-02-13T17:17:27.147Z

Link: CVE-2024-1477

cve-icon Vulnrichment

Updated: 2024-08-01T18:40:21.302Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-03-20T07:15:10.330

Modified: 2024-11-21T08:50:40.047

Link: CVE-2024-1477

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-07-12T22:00:58Z