cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forcmp-coming-soon-maintenance cmp-coming-soon-maintenance

Direction: ascending
Jun 07, 2024

CMP – Coming Soon & Maintenance Plugin by NiteoThemes # CVE-2023-1263

CVE, Research URL

CVE-2023-1263

Date
Mar 08, 2023
Research Description
The CMP – Coming Soon & Maintenance plugin for WordPress is vulnerable to Information Exposure in versions up to, and including, 4.1.6 via the cmp_get_post_detail function. This can allow unauthenticated individuals to obtain the contents of any non-password-protected, published post or page even when maintenance mode is enabled.
Affected versions
max 4.1.7.
Status
vulnerable

CMP – Coming Soon & Maintenance Plugin by NiteoThemes # CVE-2023-2159

CVE, Research URL

CVE-2023-2159

Date
Jun 09, 2023
Research Description
The CMP – Coming Soon & Maintenance plugin for WordPress is vulnerable to Maintenance Mode Bypass in versions up to, and including, 4.1.7. A correct cmp_bypass GET parameter in the URL (equal to the md5-hashed home_url in the default setting) allows users to visit a site placed in maintenance mode thus bypassing the plugin's provided feature.
Affected versions
max 4.1.8.
Status
vulnerable

CMP – Coming Soon & Maintenance Plugin by NiteoThemes # CVE-2022-0188

CVE, Research URL

CVE-2022-0188

Date
Feb 14, 2022
Research Description
The CMP WordPress plugin before 4.0.19 allows any user, even not logged in, to arbitrarily change the coming soon page layout.
Affected versions
max 4.0.19.
Status
vulnerable

CMP – Coming Soon & Maintenance Plugin by NiteoThemes # CVE-2020-36730

CVE, Research URL

CVE-2020-36730

Date
Jun 07, 2023
Research Description
The CMP for WordPress is vulnerable to authorization bypass due to a missing capability check on the cmp_get_post_detail(), niteo_export_csv(), and cmp_disable_comingsoon_ajax() functions in versions up to, and including, 3.8.1. This makes it possible for unauthenticated attackers to read posts, export subscriber lists, and/or deactivate the plugin.
Affected versions
max 3.8.2.
Status
vulnerable

CMP – Coming Soon & Maintenance Plugin by NiteoThemes # CVE-2023-50374

CVE, Research URL

CVE-2023-50374

Date
Mar 28, 2024
Research Description
Server-Side Request Forgery (SSRF) vulnerability in NiteoThemes CMP – Coming Soon & Maintenance.This issue affects CMP – Coming Soon & Maintenance: from n/a through 4.1.10.
Affected versions
max 4.1.11.
Status
vulnerable
Apr 06, 2025

CMP – Coming Soon & Maintenance Plugin by NiteoThemes # CVE-2025-32118

CVE, Research URL

CVE-2025-32118

Date
Apr 04, 2025
Research Description
Unrestricted Upload of File with Dangerous Type vulnerability in NiteoThemes CMP – Coming Soon & Maintenance cmp-coming-soon-maintenance allows Using Malicious Files.This issue affects CMP – Coming Soon & Maintenance: from n/a through <= 4.1.14.
Affected versions
max 4.1.15.
Status
vulnerable
Apr 19, 2026

CMP &#8211; Coming Soon &amp; Maintenance Plugin by NiteoThemes # CVE-2026-6518

CVE, Research URL

CVE-2026-6518

Date
Apr 18, 2026
Research Description
The CMP – Coming Soon & Maintenance Plugin by NiteoThemes plugin for WordPress is vulnerable to arbitrary file upload and remote code execution in all versions up to, and including, 4.1.16 via the `cmp_theme_update_install` AJAX action. This is due to the function only checking for the `publish_pages` capability (available to Editors and above) instead of `manage_options` (Administrators only), combined with a lack of proper validation on the user-supplied file URL and no verification of the downloaded file's content before extraction. This makes it possible for authenticated attackers, with Administrator-level access and above, to force the server to download and extract a malicious ZIP file from a remote attacker-controlled URL into a web-accessible directory (`wp-content/plugins/cmp-premium-themes/`), resulting in remote code execution. Due to the lack of a nonce for Editors, they are unable to exploit this vulnerability.
Affected versions
max 4.1.17.
Status
vulnerable
Jun 16, 2026

CMP &#8211; Coming Soon &amp; Maintenance Plugin by NiteoThemes # 493efc501edfebade2576b585bb1de86e1bbd360

Date
May 02, 2021
Research Description
CMP &#8211; Coming Soon &amp; Maintenance Plugin by NiteoThemes [cmp-coming-soon-maintenance] < 4.0.10 WordPress CMP – Coming Soon & Maintenance plugin <= 4.0.9 - Authenticated Remote Code Execution (RCE) vulnerability Remote Code Execution (RCE) vulnerability discovered by Ngo Van Thien (Sun* Cyber Security Research Team) Patchstack Red Team member in WordPress CMP – Coming Soon & Maintenance plugin (versions <= 4.0.9).
Affected versions
max 4.0.10.
Status
vulnerable

CMP &#8211; Coming Soon &amp; Maintenance Plugin by NiteoThemes # 639b237923197a567ea03b33a98c9c21d5289ddf

Date
Aug 04, 2020
Research Description
CMP &#8211; Coming Soon &amp; Maintenance Plugin by NiteoThemes [cmp-coming-soon-maintenance] < 3.8.2 WordPress CMP – Coming Soon & Maintenance plugin <= 3.8.1 - Unauthenticated Subscribers List Export vulnerability Unauthenticated Subscribers List Export vulnerability discovered by NinTechNet in WordPress CMP – Coming Soon & Maintenance plugin (versions <= 3.8.1).
Affected versions
max 3.8.2.
Status
vulnerable

CMP &#8211; Coming Soon &amp; Maintenance Plugin by NiteoThemes # cab7308aea50864d5d90d60d635c73a105eb8c65

Date
May 02, 2021
Research Description
CMP &#8211; Coming Soon &amp; Maintenance Plugin by NiteoThemes [cmp-coming-soon-maintenance] < 4.0.10 WordPress CMP – Coming Soon & Maintenance plugin <= 4.0.9 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered by Ngo Van Thien (Sun* Cyber Security Research Team) Patchstack Red Team member in WordPress CMP – Coming Soon & Maintenance plugin (versions <= 4.0.9).
Affected versions
max 4.0.10.
Status
vulnerable

CMP &#8211; Coming Soon &amp; Maintenance Plugin by NiteoThemes # dc84b51220b5e83ad578e84354a9de766cad5c4a

Date
Aug 04, 2020
Research Description
CMP &#8211; Coming Soon &amp; Maintenance Plugin by NiteoThemes [cmp-coming-soon-maintenance] < 3.8.2 WordPress CMP – Coming Soon & Maintenance plugin <= 3.8.1 - Arbitrary Post Read (draft, pending, private or even password-protected) vulnerability Arbitrary Post Read (draft, pending, private, or even password-protected) vulnerability discovered by NinTechNet in WordPress CMP – Coming Soon & Maintenance plugin (versions <= 3.8.1).
Affected versions
max 3.8.2.
Status
vulnerable

CMP &#8211; Coming Soon &amp; Maintenance Plugin by NiteoThemes # 01fd8bb276090293be00c9929b2b8f303be4636b

Date
Aug 04, 2020
Research Description
CMP &#8211; Coming Soon &amp; Maintenance Plugin by NiteoThemes [cmp-coming-soon-maintenance] < 3.8.2 WordPress CMP – Coming Soon & Maintenance plugin <= 3.8.1 - Unauthenticated Plugin Deactivation vulnerability Unauthenticated Plugin Deactivation vulnerability discovered by NinTechNet in WordPress CMP – Coming Soon & Maintenance plugin (versions <= 3.8.1).
Affected versions
max 3.8.2.
Status
vulnerable

CMP &#8211; Coming Soon &amp; Maintenance Plugin by NiteoThemes # f820452e-37f5-44b9-a232-11d9b91bec3b

Date
-
Research Description
CMP &#8211; Coming Soon &amp; Maintenance Plugin by NiteoThemes [cmp-coming-soon-maintenance] < 3.8.2 CMP - Coming Soon &amp; Maintenance &lt; 3.8.2 - Improper Access Controls on AJAX Calls Some of the AJAX calls from the plugin do not properly check for capabilities and CSRF tokens, leading to issues such as arbitrary post read, subscribers list export and plugin deactivation.
Affected versions
max 3.8.2.
Status
vulnerable

CMP &#8211; Coming Soon &amp; Maintenance Plugin by NiteoThemes # 5f4b34f29d65ad56a87c52cae5e772aead075a91

Date
Aug 04, 2020
Research Description
CMP &#8211; Coming Soon &amp; Maintenance Plugin by NiteoThemes [cmp-coming-soon-maintenance] < 3.8.2 CMP <= 3.8.1 - Missing Authorization The CMP for WordPress is vulnerable to authorization bypass due to a missing capability check on the cmp_get_post_detail(), niteo_export_csv(), and cmp_disable_comingsoon_ajax() functions in versions up to, and including, 3.8.1. This makes it possible for unauthenticated attackers to read posts, export subscriber lists, and/or deactivate the plugin.
Affected versions
max 3.8.2.
Status
vulnerable
Aug 29, 2026

CMP &#8211; Coming Soon &amp; Maintenance Plugin by NiteoThemes # CVE-2026-13414

CVE, Research URL

CVE-2026-13414

Date
Aug 27, 2026
Research Description
The CMP WordPress plugin before 4.1.18 does not perform authorization checks on one of its AJAX actions and relies on a nonce that is skipped for certain (and exposed to anonymous visitors on others), allowing unauthenticated attackers to disable the site's maintenance/coming-soon mode under a non-default countdown configuration.
Affected versions
max 4.1.18.
Status
vulnerable

CMP &#8211; Coming Soon &amp; Maintenance Plugin by NiteoThemes # CVE-2026-13416

CVE, Research URL

CVE-2026-13416

Date
Aug 27, 2026
Research Description
The CMP WordPress plugin before 4.1.18 does not sanitise and escape a settings value before outputting it on the coming-soon page, allowing users with the Editor role (when the administrator has granted the Editor role access to the CMP WordPress plugin before 4.1.18's admin-bar controls) to inject arbitrary web scripts that execute when a visitor views the page.
Affected versions
max 4.1.18.
Status
vulnerable

CMP &#8211; Coming Soon &amp; Maintenance Plugin by NiteoThemes # CVE-2026-13415

CVE, Research URL

CVE-2026-13415

Date
Aug 27, 2026
Research Description
The CMP WordPress plugin before 4.1.18 does not enforce an option-name allow-list when importing settings via one of its AJAX actions, allowing users with the Editor role (when the administrator has granted the Editor role access to the CMP WordPress plugin before 4.1.18's admin-bar controls) to update arbitrary WordPress options, including options that lead to privilege escalation to Administrator.
Affected versions
max 4.1.18.
Status
vulnerable