cleantalk
Vulnerabilities and Security Researches

CMP – Coming Soon & Maintenance Plugin by NiteoThemes, 5f4b34f29d65ad56a87c52cae5e772aead075a91

Published on
Aug 04, 2020
Research Description
CMP &#8211; Coming Soon &amp; Maintenance Plugin by NiteoThemes [cmp-coming-soon-maintenance] < 3.8.2 CMP <= 3.8.1 - Missing Authorization The CMP for WordPress is vulnerable to authorization bypass due to a missing capability check on the cmp_get_post_detail(), niteo_export_csv(), and cmp_disable_comingsoon_ajax() functions in versions up to, and including, 3.8.1. This makes it possible for unauthenticated attackers to read posts, export subscriber lists, and/or deactivate the plugin.
Affected versions
max 3.8.2.
Status
vulnerable