Vulnerabilities and security researches forcmp-coming-soon-maintenance cmp-coming-soon-maintenance
Direction: ascendingJun 07, 2024
CMP – Coming Soon & Maintenance Plugin by NiteoThemes # CVE-2023-1263
- CVE, Research URL
- Date
- Mar 08, 2023
- Research Description
- The CMP – Coming Soon & Maintenance plugin for WordPress is vulnerable to Information Exposure in versions up to, and including, 4.1.6 via the cmp_get_post_detail function. This can allow unauthenticated individuals to obtain the contents of any non-password-protected, published post or page even when maintenance mode is enabled.
- Affected versions
-
max 4.1.7.
- Status
-
vulnerable
CMP – Coming Soon & Maintenance Plugin by NiteoThemes # CVE-2023-2159
- CVE, Research URL
- Date
- Jun 09, 2023
- Research Description
- The CMP – Coming Soon & Maintenance plugin for WordPress is vulnerable to Maintenance Mode Bypass in versions up to, and including, 4.1.7. A correct cmp_bypass GET parameter in the URL (equal to the md5-hashed home_url in the default setting) allows users to visit a site placed in maintenance mode thus bypassing the plugin's provided feature.
- Affected versions
-
max 4.1.8.
- Status
-
vulnerable
CMP – Coming Soon & Maintenance Plugin by NiteoThemes # CVE-2022-0188
- CVE, Research URL
- Date
- Feb 14, 2022
- Research Description
- The CMP WordPress plugin before 4.0.19 allows any user, even not logged in, to arbitrarily change the coming soon page layout.
- Affected versions
-
max 4.0.19.
- Status
-
vulnerable
CMP – Coming Soon & Maintenance Plugin by NiteoThemes # CVE-2020-36730
- CVE, Research URL
- Date
- Jun 07, 2023
- Research Description
- The CMP for WordPress is vulnerable to authorization bypass due to a missing capability check on the cmp_get_post_detail(), niteo_export_csv(), and cmp_disable_comingsoon_ajax() functions in versions up to, and including, 3.8.1. This makes it possible for unauthenticated attackers to read posts, export subscriber lists, and/or deactivate the plugin.
- Affected versions
-
max 3.8.2.
- Status
-
vulnerable
CMP – Coming Soon & Maintenance Plugin by NiteoThemes # CVE-2023-50374
- CVE, Research URL
- Date
- Mar 28, 2024
- Research Description
- Server-Side Request Forgery (SSRF) vulnerability in NiteoThemes CMP – Coming Soon & Maintenance.This issue affects CMP – Coming Soon & Maintenance: from n/a through 4.1.10.
- Affected versions
-
max 4.1.11.
- Status
-
vulnerable
Apr 06, 2025
CMP – Coming Soon & Maintenance Plugin by NiteoThemes # CVE-2025-32118
- CVE, Research URL
- Date
- Apr 04, 2025
- Research Description
- Unrestricted Upload of File with Dangerous Type vulnerability in NiteoThemes CMP – Coming Soon & Maintenance cmp-coming-soon-maintenance allows Using Malicious Files.This issue affects CMP – Coming Soon & Maintenance: from n/a through <= 4.1.14.
- Affected versions
-
max 4.1.15.
- Status
-
vulnerable
Apr 19, 2026
CMP – Coming Soon & Maintenance Plugin by NiteoThemes # CVE-2026-6518
- CVE, Research URL
- Date
- Apr 18, 2026
- Research Description
- The CMP – Coming Soon & Maintenance Plugin by NiteoThemes plugin for WordPress is vulnerable to arbitrary file upload and remote code execution in all versions up to, and including, 4.1.16 via the `cmp_theme_update_install` AJAX action. This is due to the function only checking for the `publish_pages` capability (available to Editors and above) instead of `manage_options` (Administrators only), combined with a lack of proper validation on the user-supplied file URL and no verification of the downloaded file's content before extraction. This makes it possible for authenticated attackers, with Administrator-level access and above, to force the server to download and extract a malicious ZIP file from a remote attacker-controlled URL into a web-accessible directory (`wp-content/plugins/cmp-premium-themes/`), resulting in remote code execution. Due to the lack of a nonce for Editors, they are unable to exploit this vulnerability.
- Affected versions
-
max 4.1.17.
- Status
-
vulnerable
Jun 16, 2026
CMP – Coming Soon & Maintenance Plugin by NiteoThemes # 493efc501edfebade2576b585bb1de86e1bbd360
- CVE, Research URL
- Date
- May 02, 2021
- Research Description
- CMP – Coming Soon & Maintenance Plugin by NiteoThemes [cmp-coming-soon-maintenance] < 4.0.10 WordPress CMP – Coming Soon & Maintenance plugin <= 4.0.9 - Authenticated Remote Code Execution (RCE) vulnerability Remote Code Execution (RCE) vulnerability discovered by Ngo Van Thien (Sun* Cyber Security Research Team) Patchstack Red Team member in WordPress CMP – Coming Soon & Maintenance plugin (versions <= 4.0.9).
- Affected versions
-
max 4.0.10.
- Status
-
vulnerable
CMP – Coming Soon & Maintenance Plugin by NiteoThemes # 639b237923197a567ea03b33a98c9c21d5289ddf
- CVE, Research URL
- Date
- Aug 04, 2020
- Research Description
- CMP – Coming Soon & Maintenance Plugin by NiteoThemes [cmp-coming-soon-maintenance] < 3.8.2 WordPress CMP – Coming Soon & Maintenance plugin <= 3.8.1 - Unauthenticated Subscribers List Export vulnerability Unauthenticated Subscribers List Export vulnerability discovered by NinTechNet in WordPress CMP – Coming Soon & Maintenance plugin (versions <= 3.8.1).
- Affected versions
-
max 3.8.2.
- Status
-
vulnerable
CMP – Coming Soon & Maintenance Plugin by NiteoThemes # cab7308aea50864d5d90d60d635c73a105eb8c65
- CVE, Research URL
- Date
- May 02, 2021
- Research Description
- CMP – Coming Soon & Maintenance Plugin by NiteoThemes [cmp-coming-soon-maintenance] < 4.0.10 WordPress CMP – Coming Soon & Maintenance plugin <= 4.0.9 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered by Ngo Van Thien (Sun* Cyber Security Research Team) Patchstack Red Team member in WordPress CMP – Coming Soon & Maintenance plugin (versions <= 4.0.9).
- Affected versions
-
max 4.0.10.
- Status
-
vulnerable
CMP – Coming Soon & Maintenance Plugin by NiteoThemes # dc84b51220b5e83ad578e84354a9de766cad5c4a
- CVE, Research URL
- Date
- Aug 04, 2020
- Research Description
- CMP – Coming Soon & Maintenance Plugin by NiteoThemes [cmp-coming-soon-maintenance] < 3.8.2 WordPress CMP – Coming Soon & Maintenance plugin <= 3.8.1 - Arbitrary Post Read (draft, pending, private or even password-protected) vulnerability Arbitrary Post Read (draft, pending, private, or even password-protected) vulnerability discovered by NinTechNet in WordPress CMP – Coming Soon & Maintenance plugin (versions <= 3.8.1).
- Affected versions
-
max 3.8.2.
- Status
-
vulnerable
CMP – Coming Soon & Maintenance Plugin by NiteoThemes # 01fd8bb276090293be00c9929b2b8f303be4636b
- CVE, Research URL
- Date
- Aug 04, 2020
- Research Description
- CMP – Coming Soon & Maintenance Plugin by NiteoThemes [cmp-coming-soon-maintenance] < 3.8.2 WordPress CMP – Coming Soon & Maintenance plugin <= 3.8.1 - Unauthenticated Plugin Deactivation vulnerability Unauthenticated Plugin Deactivation vulnerability discovered by NinTechNet in WordPress CMP – Coming Soon & Maintenance plugin (versions <= 3.8.1).
- Affected versions
-
max 3.8.2.
- Status
-
vulnerable
CMP – Coming Soon & Maintenance Plugin by NiteoThemes # f820452e-37f5-44b9-a232-11d9b91bec3b
- CVE, Research URL
- Date
- -
- Research Description
- CMP – Coming Soon & Maintenance Plugin by NiteoThemes [cmp-coming-soon-maintenance] < 3.8.2 CMP - Coming Soon & Maintenance < 3.8.2 - Improper Access Controls on AJAX Calls Some of the AJAX calls from the plugin do not properly check for capabilities and CSRF tokens, leading to issues such as arbitrary post read, subscribers list export and plugin deactivation.
- Affected versions
-
max 3.8.2.
- Status
-
vulnerable
CMP – Coming Soon & Maintenance Plugin by NiteoThemes # 5f4b34f29d65ad56a87c52cae5e772aead075a91
- CVE, Research URL
- Date
- Aug 04, 2020
- Research Description
- CMP – Coming Soon & Maintenance Plugin by NiteoThemes [cmp-coming-soon-maintenance] < 3.8.2 CMP <= 3.8.1 - Missing Authorization The CMP for WordPress is vulnerable to authorization bypass due to a missing capability check on the cmp_get_post_detail(), niteo_export_csv(), and cmp_disable_comingsoon_ajax() functions in versions up to, and including, 3.8.1. This makes it possible for unauthenticated attackers to read posts, export subscriber lists, and/or deactivate the plugin.
- Affected versions
-
max 3.8.2.
- Status
-
vulnerable
Aug 29, 2026
CMP – Coming Soon & Maintenance Plugin by NiteoThemes # CVE-2026-13414
- CVE, Research URL
- Date
- Aug 27, 2026
- Research Description
- The CMP WordPress plugin before 4.1.18 does not perform authorization checks on one of its AJAX actions and relies on a nonce that is skipped for certain (and exposed to anonymous visitors on others), allowing unauthenticated attackers to disable the site's maintenance/coming-soon mode under a non-default countdown configuration.
- Affected versions
-
max 4.1.18.
- Status
-
vulnerable
CMP – Coming Soon & Maintenance Plugin by NiteoThemes # CVE-2026-13416
- CVE, Research URL
- Date
- Aug 27, 2026
- Research Description
- The CMP WordPress plugin before 4.1.18 does not sanitise and escape a settings value before outputting it on the coming-soon page, allowing users with the Editor role (when the administrator has granted the Editor role access to the CMP WordPress plugin before 4.1.18's admin-bar controls) to inject arbitrary web scripts that execute when a visitor views the page.
- Affected versions
-
max 4.1.18.
- Status
-
vulnerable
CMP – Coming Soon & Maintenance Plugin by NiteoThemes # CVE-2026-13415
- CVE, Research URL
- Date
- Aug 27, 2026
- Research Description
- The CMP WordPress plugin before 4.1.18 does not enforce an option-name allow-list when importing settings via one of its AJAX actions, allowing users with the Editor role (when the administrator has granted the Editor role access to the CMP WordPress plugin before 4.1.18's admin-bar controls) to update arbitrary WordPress options, including options that lead to privilege escalation to Administrator.
- Affected versions
-
max 4.1.18.
- Status
-
vulnerable