Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total2
Critical0
High0
Medium1
Reset
Showing 1-2 of 2 records
Threat Entry Updated 2025-10-30

CVE-2025-10636 - Ns Maintenance Mode For Wp Plugin

The NS Maintenance Mode for WP WordPress plugin through 1.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Ns Maintenance Mode For Wp

CVE-2025-10636

LOW CVSS 3.5 2025-10-30
Threat Entry Updated 2025-10-22

CVE-2025-10638 - Ns Maintenance Mode For Wp Plugin

The NS Maintenance Mode for WP WordPress plugin through 1.3.1 lacks authorization in its subscriber export function allowing unauthenticated attackers to download a list of a site's subscribers containing their name and email address

PLUGIN Ns Maintenance Mode For Wp

CVE-2025-10638

MEDIUM CVSS 5.3 2025-10-22
Scroll to top