Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Như Nguyễn

#41398of 57,248
7.2Total CVSS
Vulnerabilities · 1
PT-2026-96646
7.2
2026-09-22
Niteothemes · Cmp – Coming Soon & Maintenance Plugin · CVE-2026-12470
**Name of the Vulnerable Software and Affected Versions** CMP – Coming Soon & Maintenance Plugin by NiteoThemes versions prior to 4.1.18 **Description** An issue exists where a missing capability check on the 'cmp ajax import settings' AJAX action allows authenticated attackers with Editor-level access or higher to perform unauthorized modification of data. This flaw enables the update of arbitrary options on the WordPress site, which can be exploited to change the default registration role to administrator and enable user registration, ultimately granting the attacker administrative access to the site. **Recommendations** Update CMP – Coming Soon & Maintenance Plugin by NiteoThemes to version 4.1.18 or later. As a temporary mitigation, restrict access to the 'cmp ajax import settings' AJAX action for users with Editor-level permissions.