PT-2026-96646 · Niteothemes · Cmp – Coming Soon & Maintenance Plugin
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
CMP – Coming Soon & Maintenance Plugin by NiteoThemes versions prior to 4.1.18
Description
An issue exists where a missing capability check on the 'cmp ajax import settings' AJAX action allows authenticated attackers with Editor-level access or higher to perform unauthorized modification of data. This flaw enables the update of arbitrary options on the WordPress site, which can be exploited to change the default registration role to administrator and enable user registration, ultimately granting the attacker administrative access to the site.
Recommendations
Update CMP – Coming Soon & Maintenance Plugin by NiteoThemes to version 4.1.18 or later.
As a temporary mitigation, restrict access to the 'cmp ajax import settings' AJAX action for users with Editor-level permissions.
Fix
LPE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cmp – Coming Soon & Maintenance Plugin