PT-2026-96646 · Niteothemes · Cmp – Coming Soon & Maintenance Plugin

·

CVE-2026-12470

·

Published

2026-09-22

·

Updated

2026-09-29

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CMP – Coming Soon & Maintenance Plugin by NiteoThemes versions prior to 4.1.18
Description An issue exists where a missing capability check on the 'cmp ajax import settings' AJAX action allows authenticated attackers with Editor-level access or higher to perform unauthorized modification of data. This flaw enables the update of arbitrary options on the WordPress site, which can be exploited to change the default registration role to administrator and enable user registration, ultimately granting the attacker administrative access to the site.
Recommendations Update CMP – Coming Soon & Maintenance Plugin by NiteoThemes to version 4.1.18 or later. As a temporary mitigation, restrict access to the 'cmp ajax import settings' AJAX action for users with Editor-level permissions.

Fix

LPE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12470

Affected Products

Cmp – Coming Soon & Maintenance Plugin