VYPR
Medium severity5.3NVD Advisory· Published Oct 22, 2025· Updated Apr 15, 2026

CVE-2025-10638

CVE-2025-10638

Description

The NS Maintenance Mode for WP WordPress plugin through 1.3.1 lacks authorization in its subscriber export function allowing unauthenticated attackers to download a list of a site's subscribers containing their name and email address

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

The NS Maintenance Mode for WP plugin ≤1.3.1 exposes subscriber names and email addresses via an unauthenticated export function.

The NS Maintenance Mode for WP WordPress plugin through version 1.3.1 contains a missing authorization vulnerability in its subscriber export functionality. The plugin fails to check for proper permissions or authentication before processing a request to export subscriber data, allowing anyone to trigger this function without any credentials [1].

An unauthenticated attacker can directly call the export function via an HTTP request, and the plugin will generate a file containing subscriber information. No user interaction or administrative privileges are required for exploitation, making this easily accessible to anyone who can reach the WordPress site's endpoints [1].

As a result, an attacker can obtain a full list of the website's subscribers, including their names and email addresses. This exposure can lead to privacy violations, targeted phishing campaigns, or spam, as the data is presented in a downloadable format [1].

The vulnerability affects all versions up to and including 1.3.1. At the time of disclosure, no official fix or patched version was available, and the plugin was listed with no known fix [1]. Site administrators using this plugin are advised to remove or replace it to prevent unauthorized data leaks.

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.