The WP Maintenance Mode plugin before version 1.8.8 for WordPress had a vulnerability which allowed attackers who were not authorized to make changes to the settings of the plugin. This could have allowed attackers to take control of the accounts of other users.