3 results (0.004 seconds)

CVSS: 5.3EPSS: 0%CPEs: 1EXPL: 1

18 Apr 2023 — The CMP – Coming Soon & Maintenance plugin for WordPress is vulnerable to Maintenance Mode Bypass in versions up to, and including, 4.1.7. A correct cmp_bypass GET parameter in the URL (equal to the md5-hashed home_url in the default setting) allows users to visit a site placed in maintenance mode thus bypassing the plugin's provided feature. • https://plugins.trac.wordpress.org/browser/cmp-coming-soon-maintenance/tags/4.1.6/niteo-cmp.php#L808 • CWE-284: Improper Access Control •

CVSS: 5.3EPSS: 0%CPEs: 1EXPL: 1

17 Jan 2022 — The CMP WordPress plugin before 4.0.19 allows any user, even not logged in, to arbitrarily change the coming soon page layout. El plugin CMP de WordPress versiones anteriores a 4.0.19, permite que cualquier usuario, incluso sin haber iniciado sesión, pueda cambiar arbitrariamente el diseño de la página "coming soon" • https://plugins.trac.wordpress.org/changeset/2657597/cmp-coming-soon-maintenance • CWE-306: Missing Authentication for Critical Function CWE-862: Missing Authorization •

CVSS: 9.3EPSS: 42%CPEs: 1EXPL: 2

04 Aug 2020 — The CMP for WordPress is vulnerable to authorization bypass due to a missing capability check on the cmp_get_post_detail(), niteo_export_csv(), and cmp_disable_comingsoon_ajax() functions in versions up to, and including, 3.8.1. This makes it possible for unauthenticated attackers to read posts, export subscriber lists, and/or deactivate the plugin. • https://github.com/RandomRobbieBF/CVE-2020-36730 • CWE-862: Missing Authorization •