PT-2026-82383 · WordPress · Cmp

CVE-2026-13414

·

Published

2026-08-27

·

Updated

2026-08-27

CVSS v3.1

4.8

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions CMP WordPress plugin versions prior to 4.1.18
Description An issue exists where the plugin fails to perform authorization checks on an AJAX action. The system relies on a nonce (a unique token used to prevent replay attacks) that is skipped in some instances and exposed to anonymous visitors in others. This allows unauthenticated attackers to disable the maintenance or coming-soon mode when a non-default countdown configuration is active.
Recommendations Update the CMP WordPress plugin to version 4.1.18 or later.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-13414

Affected Products

Cmp