CMP – Coming Soon & Maintenance Plugin by NiteoThemes, 5f4b34f29d65ad56a87c52cae5e772aead075a91
- CVE, Research URL
- Published on
- Aug 04, 2020
- Research Description
- CMP – Coming Soon & Maintenance Plugin by NiteoThemes [cmp-coming-soon-maintenance] < 3.8.2 CMP <= 3.8.1 - Missing Authorization The CMP for WordPress is vulnerable to authorization bypass due to a missing capability check on the cmp_get_post_detail(), niteo_export_csv(), and cmp_disable_comingsoon_ajax() functions in versions up to, and including, 3.8.1. This makes it possible for unauthenticated attackers to read posts, export subscriber lists, and/or deactivate the plugin.
- Affected versions
-
max 3.8.2.
- Status
-
vulnerable