PT-2026-82385 · WordPress · Cmp
CVE-2026-13416
·
Published
2026-08-27
·
Updated
2026-08-27
CVSS v3.1
3.5
Low
| Vector | AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
CMP WordPress plugin versions prior to 4.1.18
Description
Insufficient sanitization and escaping of a settings value before it is output on the coming-soon page allows users with the Editor role to perform a Cross-Site Scripting (XSS) attack. This occurs when the administrator has granted the Editor role access to the plugin's admin-bar controls, enabling the injection of arbitrary web scripts that execute when a visitor views the page.
Recommendations
Update CMP WordPress plugin to version 4.1.18 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cmp