Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 28 Apr 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-200 CWE-284 |
Thu, 23 Oct 2025 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress |
|
| Vendors & Products |
Wordpress
Wordpress wordpress |
Wed, 22 Oct 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 22 Oct 2025 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The NS Maintenance Mode for WP WordPress plugin through 1.3.1 lacks authorization in its subscriber export function allowing unauthenticated attackers to download a list of a site's subscribers containing their name and email address | |
| Title | NS Maintenance Mode for WP <= 1.3.1 - Unauthenticated Subscribers Export | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-04-02T12:39:50.738Z
Reserved: 2025-09-17T13:34:17.993Z
Link: CVE-2025-10638
Updated: 2025-10-22T15:42:38.157Z
Status : Deferred
Published: 2025-10-22T06:15:30.593
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-10638
No data.
OpenCVE Enrichment
Updated: 2026-04-27T23:45:15Z