Boletines de Vulnerabilidades

CVE-2025-10638

   
Software afectado WORDPRESS
 
The NS Maintenance Mode for WP WordPress plugin through 1.3.1 lacks authorization in its subscriber export function allowing unauthenticated attackers to download a list of a site's subscribers containing their name and email address

Link:

https://nvd.nist.gov/vuln/detail/CVE-2025-10638