CMP – Coming Soon & Maintenance Plugin by NiteoThemes <= 4.1.16 - Missing Authorization to Authenticated (Administrator+) Arbitrary File Upload and Remote Code Execution
high
The CMP – Coming Soon & Maintenance Plugin by NiteoThemes plugin for WordPress is vulnerable to arbitrary file upload and remote code execution in all versions up to, and including, 4.1.16 via the `cmp_theme_update_install` AJAX action. This is due to the function only checking for the `publish_pages` capability (avail...
- CVSS:
- 8.8
- Affected:
- up to 4.1.16
- Fixed in:
- 4.1.17
- Disclosed:
- Apr 17, 2026
CVE-2026-6518 on NVD →
CMP – Coming Soon & Maintenance <= 4.1.13 - Authenticated (Admin+) Arbitrary File Upload
high
The CMP – Coming Soon & Maintenance Plugin by NiteoThemes plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 4.1.13. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary file...
- CVSS:
- 7.2
- Affected:
- up to 4.1.13
- Fixed in:
- 4.1.15
- Disclosed:
- Apr 4, 2025
CVE-2025-32118 on NVD →
CMP – Coming Soon & Maintenance Plugin by NiteoThemes [cmp-coming-soon-maintenance] < 4.1.15
unknown
[en] Unrestricted Upload of File with Dangerous Type vulnerability in NiteoThemes CMP – Coming Soon & Maintenance allows Using Malicious Files. This issue affects CMP – Coming Soon & Maintenance: from n/a through 4.1.13.
- Affected:
- up to 4.1.15
- Fixed in:
- 4.1.15
- Disclosed:
- Apr 4, 2025
CVE-2025-32118 on NVD →
CMP – Coming Soon & Maintenance Plugin by NiteoThemes [cmp-coming-soon-maintenance] < 4.1.11
unknown
[en] Server-Side Request Forgery (SSRF) vulnerability in NiteoThemes CMP – Coming Soon & Maintenance.This issue affects CMP – Coming Soon & Maintenance: from n/a through 4.1.10.
- Affected:
- up to 4.1.11
- Fixed in:
- 4.1.11
- Disclosed:
- Mar 28, 2024
CVE-2023-50374 on NVD →
CMP – Coming Soon & Maintenance <= 4.1.10 - Authenticated (Admin+) Server-Side Request Forgery
medium
The CMP – Coming Soon & Maintenance Plugin by NiteoThemes plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.1.10. This makes it possible for authenticated attackers, with administrator-level access and above, to make web requests to arbitrary locations originating...
- CVSS:
- 5.5
- Affected:
- up to 4.1.10
- Fixed in:
- 4.1.11
- Disclosed:
- Mar 27, 2024
CVE-2023-50374 on NVD →
CMP – Coming Soon & Maintenance Plugin by NiteoThemes [cmp-coming-soon-maintenance] < 4.1.8
unknown
[en] The CMP – Coming Soon & Maintenance plugin for WordPress is vulnerable to Maintenance Mode Bypass in versions up to, and including, 4.1.7. A correct cmp_bypass GET parameter in the URL (equal to the md5-hashed home_url in the default setting) allows users to visit a site placed in maintenance mode thus bypassing t...
- Affected:
- up to 4.1.8
- Fixed in:
- 4.1.8
- Disclosed:
- Jun 9, 2023
CVE-2023-2159 on NVD →
CMP – Coming Soon & Maintenance Plugin by NiteoThemes [cmp-coming-soon-maintenance] < 3.8.2
unknown
[en] The CMP for WordPress is vulnerable to authorization bypass due to a missing capability check on the cmp_get_post_detail(), niteo_export_csv(), and cmp_disable_comingsoon_ajax() functions in versions up to, and including, 3.8.1. This makes it possible for unauthenticated attackers to read posts, export subscriber...
- Affected:
- up to 3.8.2
- Fixed in:
- 3.8.2
- Disclosed:
- Jun 7, 2023
CVE-2020-36730 on NVD →
CMP – Coming Soon & Maintenance <= 4.1.7 - Maintenance Mode Bypass
medium
The CMP – Coming Soon & Maintenance plugin for WordPress is vulnerable to Maintenance Mode Bypass in versions up to, and including, 4.1.7. A correct cmp_bypass GET parameter in the URL (equal to the md5-hashed home_url in the default setting) allows users to visit a site placed in maintenance mode thus bypassing the pl...
- CVSS:
- 5.3
- Affected:
- up to 4.1.7
- Fixed in:
- 4.1.8
- Disclosed:
- Apr 18, 2023
CVE-2023-2159 on NVD →
CMP – Coming Soon & Maintenance Plugin by NiteoThemes <= 4.1.6 - Information Exposure
medium
The CMP – Coming Soon & Maintenance plugin for WordPress is vulnerable to Information Exposure in versions up to, and including, 4.1.6 via the cmp_get_post_detail function. This can allow unauthenticated individuals to obtain the contents of any non-password-protected, published post or page even when maintenance mode...
- CVSS:
- 5.3
- Affected:
- up to 4.1.6
- Fixed in:
- 4.1.7
- Disclosed:
- Mar 7, 2023
CVE-2023-1263 on NVD →
CMP – Coming Soon & Maintenance Plugin by NiteoThemes [cmp-coming-soon-maintenance] < 4.1.7
unknown
[en] The CMP – Coming Soon & Maintenance plugin for WordPress is vulnerable to Information Exposure in versions up to, and including, 4.1.6 via the cmp_get_post_detail function. This can allow unauthenticated individuals to obtain the contents of any non-password-protected, published post or page even when maintenance...
- Affected:
- up to 4.1.7
- Fixed in:
- 4.1.7
- Disclosed:
- Mar 7, 2023
CVE-2023-1263 on NVD →
CMP – Coming Soon & Maintenance Plugin by NiteoThemes [cmp-coming-soon-maintenance] < 4.0.19
unknown
[en] The CMP WordPress plugin before 4.0.19 allows any user, even not logged in, to arbitrarily change the coming soon page layout.
- Affected:
- up to 4.0.19
- Fixed in:
- 4.0.19
- Disclosed:
- Feb 14, 2022
CVE-2022-0188 on NVD →
CMP - Coming Soon & Maintenance Plugin <= 4.0.18 - Unauthenticated Arbitrary CSS Update
medium
The CMP WordPress plugin before 4.0.19 allows any user, even not logged in, to arbitrarily change the coming soon page layout.
- CVSS:
- 5.3
- Affected:
- up to 4.0.19
- Fixed in:
- 4.0.19
- Disclosed:
- Jan 17, 2022
CVE-2022-0188 on NVD →
CMP – Coming Soon & Maintenance Plugin by NiteoThemes [cmp-coming-soon-maintenance] < 4.0.10
unknown
Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered by Ngo Van Thien (Sun* Cyber Security Research Team) Patchstack Red Team member in WordPress CMP – Coming Soon & Maintenance plugin (versions <= 4.0.9).
- Affected:
- up to 4.0.10
- Fixed in:
- 4.0.10
- Disclosed:
- May 2, 2021
CMP – Coming Soon & Maintenance Plugin by NiteoThemes [cmp-coming-soon-maintenance] < 4.0.10
unknown
Remote Code Execution (RCE) vulnerability discovered by Ngo Van Thien (Sun* Cyber Security Research Team) Patchstack Red Team member in WordPress CMP – Coming Soon & Maintenance plugin (versions <= 4.0.9).
- Affected:
- up to 4.0.10
- Fixed in:
- 4.0.10
- Disclosed:
- May 2, 2021
CMP <= 3.8.1 - Missing Authorization
high
The CMP for WordPress is vulnerable to authorization bypass due to a missing capability check on the cmp_get_post_detail(), niteo_export_csv(), and cmp_disable_comingsoon_ajax() functions in versions up to, and including, 3.8.1. This makes it possible for unauthenticated attackers to read posts, export subscriber lists...
- CVSS:
- 8.3
- Affected:
- up to 3.8.1
- Fixed in:
- 3.8.2
- Disclosed:
- Aug 4, 2020
CVE-2020-36730 on NVD →
CMP – Coming Soon & Maintenance Plugin by NiteoThemes [cmp-coming-soon-maintenance] < 3.8.2
unknown
Arbitrary Post Read (draft, pending, private, or even password-protected) vulnerability discovered by NinTechNet in WordPress CMP – Coming Soon & Maintenance plugin (versions <= 3.8.1).
- Affected:
- up to 3.8.2
- Fixed in:
- 3.8.2
- Disclosed:
- Aug 4, 2020
CMP – Coming Soon & Maintenance Plugin by NiteoThemes [cmp-coming-soon-maintenance] < 3.8.2
unknown
Unauthenticated Subscribers List Export vulnerability discovered by NinTechNet in WordPress CMP – Coming Soon & Maintenance plugin (versions <= 3.8.1).
- Affected:
- up to 3.8.2
- Fixed in:
- 3.8.2
- Disclosed:
- Aug 4, 2020
CMP – Coming Soon & Maintenance Plugin by NiteoThemes [cmp-coming-soon-maintenance] < 3.8.2
unknown
Unauthenticated Plugin Deactivation vulnerability discovered by NinTechNet in WordPress CMP – Coming Soon & Maintenance plugin (versions <= 3.8.1).
- Affected:
- up to 3.8.2
- Fixed in:
- 3.8.2
- Disclosed:
- Aug 4, 2020
CMP – Coming Soon & Maintenance Plugin by NiteoThemes [cmp-coming-soon-maintenance] < 3.8.2
unknown
The CMP for WordPress is vulnerable to authorization bypass due to a missing capability check on the cmp_get_post_detail(), niteo_export_csv(), and cmp_disable_comingsoon_ajax() functions in versions up to, and including, 3.8.1. This makes it possible for unauthenticated attackers to read posts, export subscriber lists...
- Affected:
- up to 3.8.2
- Fixed in:
- 3.8.2
- Disclosed:
- Aug 4, 2020
CMP – Coming Soon & Maintenance Plugin by NiteoThemes [cmp-coming-soon-maintenance] < 3.8.2
unknown
Some of the AJAX calls from the plugin do not properly check for capabilities and CSRF tokens, leading to issues such as arbitrary post read, subscribers list export and plugin deactivation.
- Affected:
- up to 3.8.2
- Fixed in:
- 3.8.2
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database