CVE-2018-20155: Designmodo Wp Maintenance Mode

Medium severity, CVSS 4.3. EPSS: 0.8% chance of exploitation in the next 30 days.

The WP Maintenance Mode plugin before 2.0.7 for WordPress allows remote authenticated subscriber users to bypass intended access restrictions on changes to plugin settings.

Affected products

  • Designmodo Wp Maintenance Mode: before 2.0.7 (fixed in 2.0.7)

Published 2018-12-14. Last modified 2026-06-17.