Description
The NS Maintenance Mode for WP WordPress plugin through 1.3.1 lacks authorization in its subscriber export function allowing unauthenticated attackers to download a list of a site's subscribers containing their name and email address
Problem types
Product status
Any version
Credits
Khaled Alenazi (Nxploited)
WPScan
References
wpscan.com/...rability/1998a079-d986-47fe-907f-d4d295b06603/