Extension WordPress
Vulnérabilités CMP – Coming Soon & Maintenance Plugin by NiteoThemes
Cette page rassemble les failles publiées pour CMP – Coming Soon & Maintenance Plugin by NiteoThemes, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de CMP – Coming Soon & Maintenance Plugin by NiteoThemes
7 fiches
CMP – Coming Soon & Maintenance Plugin by NiteoThemes <= 4.1.16 – Missing Authorization to Authenticated (Administrator+) Arbitrary File Upload and Remote Code Execution
The CMP – Coming Soon & Maintenance Plugin by NiteoThemes plugin for WordPress is vulnerable to arbitrary file upload and remote code execution in all versions up to, and including, 4.1.16 via the `cmp_theme_update_install` AJAX action. This is…
*-4.1.16
4.1.17
17/04/2026
CMP – Coming Soon & Maintenance <= 4.1.13 – Authenticated (Admin+) Arbitrary File Upload
The CMP – Coming Soon & Maintenance Plugin by NiteoThemes plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 4.1.13. This makes it possible for…
*-4.1.13
4.1.15
04/04/2025
CMP – Coming Soon & Maintenance <= 4.1.10 – Authenticated (Admin+) Server-Side Request Forgery
The CMP – Coming Soon & Maintenance Plugin by NiteoThemes plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.1.10. This makes it possible for authenticated attackers, with administrator-level access and…
*-4.1.10
4.1.11
27/03/2024
CMP – Coming Soon & Maintenance <= 4.1.7 – Maintenance Mode Bypass
The CMP – Coming Soon & Maintenance plugin for WordPress is vulnerable to Maintenance Mode Bypass in versions up to, and including, 4.1.7. A correct cmp_bypass GET parameter in the URL (equal to the md5-hashed home_url in the…
*-4.1.7
4.1.8
18/04/2023
CMP – Coming Soon & Maintenance Plugin by NiteoThemes <= 4.1.6 – Information Exposure
The CMP – Coming Soon & Maintenance plugin for WordPress is vulnerable to Information Exposure in versions up to, and including, 4.1.6 via the cmp_get_post_detail function. This can allow unauthenticated individuals to obtain the contents of any non-password-protected,…
*-4.1.6
4.1.7
07/03/2023
CMP – Coming Soon & Maintenance Plugin <= 4.0.18 – Unauthenticated Arbitrary CSS Update
The CMP WordPress plugin before 4.0.19 allows any user, even not logged in, to arbitrarily change the coming soon page layout.
[*, 4.0.19)
4.0.19
17/01/2022
CMP <= 3.8.1 – Missing Authorization
The CMP for WordPress is vulnerable to authorization bypass due to a missing capability check on the cmp_get_post_detail(), niteo_export_csv(), and cmp_disable_comingsoon_ajax() functions in versions up to, and including, 3.8.1. This makes it possible for unauthenticated attackers to read…
*-3.8.1
3.8.2
04/08/2020
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.