The WP Maintenance Mode plugin before 2.0.7 for WordPress allows remote authenticated "site administrator" users to execute arbitrary PHP code throughout a multisite network.
https://www.wordfence.com/blog/2016/07/3-vulnerabilities-wp-maintenance-mode/