Security Advisory

CVE-2025-10638

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-10-22 06:00:02
Last updated 2026-04-02 12:39:50
Assigner WPScan
CVSS score not scored
State PUBLISHED

Description

The NS Maintenance Mode for WP WordPress plugin through 1.3.1 lacks authorization in its subscriber export function allowing unauthenticated attackers to download a list of a site's subscribers containing their name and email address