The NS Maintenance Mode for WP WordPress plugin through 1.3.1 lacks authorization in its subscriber export function allowing unauthenticated attackers to download a list of a site's subscribers containing their name and email address
https://wpscan.com/vulnerability/1998a079-d986-47fe-907f-d4d295b06603/