5.3
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Description
The NS Maintenance Mode for WP WordPress plugin through 1.3.1 lacks authorization in its subscriber export function allowing unauthenticated attackers to download a list of a site's subscribers containing their name and email address
Basic Information
ID
CVE-2025-10638
Source
WPScan
Published
Oct 22, 2025 at 06:00
Modified
Oct 22, 2025 at 15:42
Affected Product
Vendor
Unknown
Product
NS Maintenance Mode for WP
Affected Versions
Unknown NS Maintenance Mode for WP 0