plugin

Cmp Coming Soon Maintenance Vulnerabilities

20 known security issues reported for the Cmp Coming Soon Maintenance WordPress plugin. Most recent disclosed Apr 17, 2026.

3 high 4 medium

Running Cmp Coming Soon Maintenance on your site? Check whether your installed version is affected.

Scan your site free

CMP – Coming Soon & Maintenance Plugin by NiteoThemes <= 4.1.16 - Missing Authorization to Authenticated (Administrator+) Arbitrary File Upload and Remote Code Execution

high

The CMP – Coming Soon & Maintenance Plugin by NiteoThemes plugin for WordPress is vulnerable to arbitrary file upload and remote code execution in all versions up to, and including, 4.1.16 via the `cmp_theme_update_install` AJAX action. This is due to the function only checking for the `publish_pages` capability (avail...

CVSS:
8.8
Affected:
up to 4.1.16
Fixed in:
4.1.17
Disclosed:
Apr 17, 2026

CVE-2026-6518 on NVD →

CMP – Coming Soon & Maintenance <= 4.1.13 - Authenticated (Admin+) Arbitrary File Upload

high

The CMP – Coming Soon & Maintenance Plugin by NiteoThemes plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 4.1.13. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary file...

CVSS:
7.2
Affected:
up to 4.1.13
Fixed in:
4.1.15
Disclosed:
Apr 4, 2025

CVE-2025-32118 on NVD →

CMP &#8211; Coming Soon &amp; Maintenance Plugin by NiteoThemes [cmp-coming-soon-maintenance] < 4.1.15

unknown

[en] Unrestricted Upload of File with Dangerous Type vulnerability in NiteoThemes CMP – Coming Soon & Maintenance allows Using Malicious Files. This issue affects CMP – Coming Soon & Maintenance: from n/a through 4.1.13.

Affected:
up to 4.1.15
Fixed in:
4.1.15
Disclosed:
Apr 4, 2025

CVE-2025-32118 on NVD →

CMP &#8211; Coming Soon &amp; Maintenance Plugin by NiteoThemes [cmp-coming-soon-maintenance] < 4.1.11

unknown

[en] Server-Side Request Forgery (SSRF) vulnerability in NiteoThemes CMP – Coming Soon & Maintenance.This issue affects CMP – Coming Soon & Maintenance: from n/a through 4.1.10.

Affected:
up to 4.1.11
Fixed in:
4.1.11
Disclosed:
Mar 28, 2024

CVE-2023-50374 on NVD →

CMP – Coming Soon & Maintenance <= 4.1.10 - Authenticated (Admin+) Server-Side Request Forgery

medium

The CMP – Coming Soon & Maintenance Plugin by NiteoThemes plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.1.10. This makes it possible for authenticated attackers, with administrator-level access and above, to make web requests to arbitrary locations originating...

CVSS:
5.5
Affected:
up to 4.1.10
Fixed in:
4.1.11
Disclosed:
Mar 27, 2024

CVE-2023-50374 on NVD →

CMP &#8211; Coming Soon &amp; Maintenance Plugin by NiteoThemes [cmp-coming-soon-maintenance] < 4.1.8

unknown

[en] The CMP – Coming Soon & Maintenance plugin for WordPress is vulnerable to Maintenance Mode Bypass in versions up to, and including, 4.1.7. A correct cmp_bypass GET parameter in the URL (equal to the md5-hashed home_url in the default setting) allows users to visit a site placed in maintenance mode thus bypassing t...

Affected:
up to 4.1.8
Fixed in:
4.1.8
Disclosed:
Jun 9, 2023

CVE-2023-2159 on NVD →

CMP &#8211; Coming Soon &amp; Maintenance Plugin by NiteoThemes [cmp-coming-soon-maintenance] < 3.8.2

unknown

[en] The CMP for WordPress is vulnerable to authorization bypass due to a missing capability check on the cmp_get_post_detail(), niteo_export_csv(), and cmp_disable_comingsoon_ajax() functions in versions up to, and including, 3.8.1. This makes it possible for unauthenticated attackers to read posts, export subscriber...

Affected:
up to 3.8.2
Fixed in:
3.8.2
Disclosed:
Jun 7, 2023

CVE-2020-36730 on NVD →

CMP – Coming Soon & Maintenance <= 4.1.7 - Maintenance Mode Bypass

medium

The CMP – Coming Soon & Maintenance plugin for WordPress is vulnerable to Maintenance Mode Bypass in versions up to, and including, 4.1.7. A correct cmp_bypass GET parameter in the URL (equal to the md5-hashed home_url in the default setting) allows users to visit a site placed in maintenance mode thus bypassing the pl...

CVSS:
5.3
Affected:
up to 4.1.7
Fixed in:
4.1.8
Disclosed:
Apr 18, 2023

CVE-2023-2159 on NVD →

CMP – Coming Soon & Maintenance Plugin by NiteoThemes <= 4.1.6 - Information Exposure

medium

The CMP – Coming Soon & Maintenance plugin for WordPress is vulnerable to Information Exposure in versions up to, and including, 4.1.6 via the cmp_get_post_detail function. This can allow unauthenticated individuals to obtain the contents of any non-password-protected, published post or page even when maintenance mode...

CVSS:
5.3
Affected:
up to 4.1.6
Fixed in:
4.1.7
Disclosed:
Mar 7, 2023

CVE-2023-1263 on NVD →

CMP &#8211; Coming Soon &amp; Maintenance Plugin by NiteoThemes [cmp-coming-soon-maintenance] < 4.1.7

unknown

[en] The CMP – Coming Soon & Maintenance plugin for WordPress is vulnerable to Information Exposure in versions up to, and including, 4.1.6 via the cmp_get_post_detail function. This can allow unauthenticated individuals to obtain the contents of any non-password-protected, published post or page even when maintenance...

Affected:
up to 4.1.7
Fixed in:
4.1.7
Disclosed:
Mar 7, 2023

CVE-2023-1263 on NVD →

CMP &#8211; Coming Soon &amp; Maintenance Plugin by NiteoThemes [cmp-coming-soon-maintenance] < 4.0.19

unknown

[en] The CMP WordPress plugin before 4.0.19 allows any user, even not logged in, to arbitrarily change the coming soon page layout.

Affected:
up to 4.0.19
Fixed in:
4.0.19
Disclosed:
Feb 14, 2022

CVE-2022-0188 on NVD →

CMP - Coming Soon & Maintenance Plugin <= 4.0.18 - Unauthenticated Arbitrary CSS Update

medium

The CMP WordPress plugin before 4.0.19 allows any user, even not logged in, to arbitrarily change the coming soon page layout.

CVSS:
5.3
Affected:
up to 4.0.19
Fixed in:
4.0.19
Disclosed:
Jan 17, 2022

CVE-2022-0188 on NVD →

CMP &#8211; Coming Soon &amp; Maintenance Plugin by NiteoThemes [cmp-coming-soon-maintenance] < 4.0.10

unknown

Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered by Ngo Van Thien (Sun* Cyber Security Research Team) Patchstack Red Team member in WordPress CMP – Coming Soon & Maintenance plugin (versions <= 4.0.9).

Affected:
up to 4.0.10
Fixed in:
4.0.10
Disclosed:
May 2, 2021

CMP &#8211; Coming Soon &amp; Maintenance Plugin by NiteoThemes [cmp-coming-soon-maintenance] < 4.0.10

unknown

Remote Code Execution (RCE) vulnerability discovered by Ngo Van Thien (Sun* Cyber Security Research Team) Patchstack Red Team member in WordPress CMP – Coming Soon & Maintenance plugin (versions <= 4.0.9).

Affected:
up to 4.0.10
Fixed in:
4.0.10
Disclosed:
May 2, 2021

CMP <= 3.8.1 - Missing Authorization

high

The CMP for WordPress is vulnerable to authorization bypass due to a missing capability check on the cmp_get_post_detail(), niteo_export_csv(), and cmp_disable_comingsoon_ajax() functions in versions up to, and including, 3.8.1. This makes it possible for unauthenticated attackers to read posts, export subscriber lists...

CVSS:
8.3
Affected:
up to 3.8.1
Fixed in:
3.8.2
Disclosed:
Aug 4, 2020

CVE-2020-36730 on NVD →

CMP &#8211; Coming Soon &amp; Maintenance Plugin by NiteoThemes [cmp-coming-soon-maintenance] < 3.8.2

unknown

Arbitrary Post Read (draft, pending, private, or even password-protected) vulnerability discovered by NinTechNet in WordPress CMP – Coming Soon & Maintenance plugin (versions <= 3.8.1).

Affected:
up to 3.8.2
Fixed in:
3.8.2
Disclosed:
Aug 4, 2020

CMP &#8211; Coming Soon &amp; Maintenance Plugin by NiteoThemes [cmp-coming-soon-maintenance] < 3.8.2

unknown

Unauthenticated Subscribers List Export vulnerability discovered by NinTechNet in WordPress CMP – Coming Soon & Maintenance plugin (versions <= 3.8.1).

Affected:
up to 3.8.2
Fixed in:
3.8.2
Disclosed:
Aug 4, 2020

CMP &#8211; Coming Soon &amp; Maintenance Plugin by NiteoThemes [cmp-coming-soon-maintenance] < 3.8.2

unknown

Unauthenticated Plugin Deactivation vulnerability discovered by NinTechNet in WordPress CMP – Coming Soon & Maintenance plugin (versions <= 3.8.1).

Affected:
up to 3.8.2
Fixed in:
3.8.2
Disclosed:
Aug 4, 2020

CMP &#8211; Coming Soon &amp; Maintenance Plugin by NiteoThemes [cmp-coming-soon-maintenance] < 3.8.2

unknown

The CMP for WordPress is vulnerable to authorization bypass due to a missing capability check on the cmp_get_post_detail(), niteo_export_csv(), and cmp_disable_comingsoon_ajax() functions in versions up to, and including, 3.8.1. This makes it possible for unauthenticated attackers to read posts, export subscriber lists...

Affected:
up to 3.8.2
Fixed in:
3.8.2
Disclosed:
Aug 4, 2020

CMP &#8211; Coming Soon &amp; Maintenance Plugin by NiteoThemes [cmp-coming-soon-maintenance] < 3.8.2

unknown

Some of the AJAX calls from the plugin do not properly check for capabilities and CSRF tokens, leading to issues such as arbitrary post read, subscribers list export and plugin deactivation.

Affected:
up to 3.8.2
Fixed in:
3.8.2

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database