PT-2026-82383 · WordPress · Cmp
CVE-2026-13414
·
Published
2026-08-27
·
Updated
2026-08-27
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
CMP WordPress plugin versions prior to 4.1.18
Description
An issue exists where the plugin fails to perform authorization checks on an AJAX action. The system relies on a nonce (a unique token used to prevent replay attacks) that is skipped in some instances and exposed to anonymous visitors in others. This allows unauthenticated attackers to disable the maintenance or coming-soon mode when a non-default countdown configuration is active.
Recommendations
Update the CMP WordPress plugin to version 4.1.18 or later.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cmp