Description
WordPress Plugin WP Maintenance Mode & Site Under Construction is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently install arbitrary plugins. WordPress Plugin WP Maintenance Mode & Site Under Construction version 1.8.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.8.2 or latest
References
Related Vulnerabilities
WordPress Plugin Google Maps Ready! Cross-Site Request Forgery (1.1.5)
WordPress 5.8.x Multiple Vulnerabilities (5.8 - 5.8.8)
WordPress Plugin SEO by Squirrly SEO SQL Injection (12.3.19)
WordPress Plugin BuddyPress Information Disclosure (5.1.1)
WordPress Plugin GiveWP-Donation and Fundraising Platform Security Bypass (2.5.9)